Patents Assigned to Zimperium, Inc.
  • Patent number: 12670238
    Abstract: A system and a method are disclosed for providing a code obfuscation solution. The system accesses a computer program comprising a set of instructions and a sequence in which the set of instructions are to be performed. The system determines a plurality of computing resources available to perform the set of instructions and assigns the set of instructions to be distributed among the computing resources for execution. A single one of the plurality of computing resources is computationally capable of performing an entirety of the set of instructions. The system modifies the set of instructions with at least one obfuscating instruction that instructs at runtime for the computer program to jump from one computing resource to another computing resource of the set of computing resources. The system transmits the set of modified instruction to a target device for executing the computer program.
    Type: Grant
    Filed: December 2, 2025
    Date of Patent: June 30, 2026
    Assignee: Zimperium, Inc.
    Inventors: Antonio Nappa, Grant Stewart Goodes, Javier Lopez Gomez
  • Patent number: 12634333
    Abstract: A system and a method are disclosed for generating protection actions to protect a target application. The system scans a target application to detect a potential risk associated with one or more chunks of code in the target application and determines configuration information of the one or more chunks of code. The system may input scanning results and the configuration information into machine learning models and receive an output including the one or more protection actions. The system applies the protection actions to the target application. Responsive to completing the one or more protection actions, the system re-scans the target application to determine a result of applying the one or more protection actions on the target application.
    Type: Grant
    Filed: July 15, 2025
    Date of Patent: May 19, 2026
    Assignee: Zimperium, Inc.
    Inventors: Grant Stewart Goodes, Nicolás Chiaraviglio, Jonathan Paterson
  • Patent number: 12547425
    Abstract: A system and a method are disclosed for identifying libraries used by an application based on the program code of the application. The system accesses a plurality of program codes of the application. For at least one program code, the system extracts raw type data from the program code and normalizes the raw type data to generate target normalized type data. The target normalized type data includes data type information of the program code. The system determines a set of candidate library types corresponding to the program code. The system accesses candidate raw type data associated with each candidate library type and determines a library type corresponding to the program code by comparing the program code of the application with the program code of each of the set of the candidate library types.
    Type: Grant
    Filed: April 30, 2024
    Date of Patent: February 10, 2026
    Assignee: Zimperium, Inc.
    Inventors: Duncan Ogilvie, Matteo Favaro, Nicolás Chiaraviglio, Jose Fernandez Portal
  • Patent number: 12493541
    Abstract: A system and a method are disclosed for providing a lightweight code integrity solution. The system identifies one or more target code blocks in program code and determines one or more locations in the program code where an integrity check is to be embedded to verify the integrity of the code block. The system may determine an integer value associated with a byte-pattern of machine-code instructions in the code blocks and generates the integrity check by entangling the integer value into one or more computations of the program code. The system embeds the integrity check at the determined location in the program code.
    Type: Grant
    Filed: February 10, 2025
    Date of Patent: December 9, 2025
    Assignee: Zimperium, Inc.
    Inventors: Grant Stewart Goodes, Javier Lopez Gomez, Ričards Dzenis, Peteris Ledins
  • Patent number: 12425418
    Abstract: A system and a method are disclosed for detecting a malicious website. In an embodiment, a computing device detects a uniform resource locator (URL) referencing an unknown website; pre-processes the URL to determine a first probability that the unknown website is malicious; and inputs the first probability into a machine learning model to receive a second probability that the unknown website is malicious. The machine learning model is trained using Secure Sockets Layer (SSL) certificates of known legitimate websites and known malicious websites. The computing device further determines whether the second probability is associated with at least a threshold risk. Responsive to the second probability being associated with at least the threshold risk, the computing device causes a graphical user interface of a client device to display a notification indicating a level of risk associated with the unknown website.
    Type: Grant
    Filed: August 31, 2022
    Date of Patent: September 23, 2025
    Assignee: Zimperium, Inc.
    Inventors: Nicolás Chiaraviglio, Santiago Andrés Rodriguez Gonzalez
  • Patent number: 12407491
    Abstract: A system and a method are disclosed for performing encryptions with pre- and post-standard data transformations. The system receives an input that includes cleartext data. The system may apply a pre-encryption to the input by performing one or more rounds of data transformations, and the pre-encryption transforms the cleartext data into non-cleartext data. The system applies a core encryption to the non-cleartext data. The core encryption includes a standard cipher algorithm that transforms the non-cleartext data into encrypted ciphertext. The system then applies a post-encryption to the encrypted ciphertext. The post-encryption includes one or more rounds of additional data transformations. The system generates an encryption of the input at a local client device based on an output from the post-encryption. In some embodiments, the pre-encryption, core encryption and post-encryption are under a White-box encryption to protect intermediate data.
    Type: Grant
    Filed: December 20, 2024
    Date of Patent: September 2, 2025
    Assignee: Zimperium, Inc.
    Inventors: Atis Straujums, Nikita Larka, Māris Valdats
  • Patent number: 12375923
    Abstract: System and methods are disclosed herein for dynamic detection of malicious activities on a mobile device. The mobile device maintains a file that is executable on the mobile device. The file includes a plurality of primitives, with each primitive comprising a piece of detection logic that, when executed, performs a security function on the mobile device. The mobile device receives instructions from a security service to chain a subset of primitives. The subset of primitives, when chained together, forms a detection process for a malicious activity newly identified by the security service. The system and methods then chain the subset of primitives based on instructions received from the security service and identify the malicious activity by executing the chained subset of primitives.
    Type: Grant
    Filed: April 30, 2024
    Date of Patent: July 29, 2025
    Assignee: Zimperium, Inc.
    Inventors: Ryan Chazen, Asaf Peleg
  • Patent number: 12010517
    Abstract: System and methods are disclosed herein for dynamic detection of malicious activities on a mobile device. The mobile device maintains a file that is executable on the mobile device. The file includes a plurality of primitives, with each primitive comprising a piece of detection logic that, when executed, performs a security function on the mobile device. The mobile device receives instructions from a security service to chain a subset of primitives. The subset of primitives, when chained together, forms a detection process for a malicious activity newly identified by the security service. The system and methods then chain the subset of primitives based on instructions received from the security service and identify the malicious activity by executing the chained subset of primitives.
    Type: Grant
    Filed: May 10, 2021
    Date of Patent: June 11, 2024
    Assignee: Zimperium, Inc.
    Inventors: Ryan Chazen, Asaf Peleg
  • Patent number: 11870808
    Abstract: A system and a method are disclosed for detecting a malicious website. In an embodiment, a mobile device detects a URL referencing an unknown website. Responsive to detecting the URL, the mobile device retrieves a representative image of the unknown website. The mobile device determines whether the representative image matches an image of a known legitimate website. Responsive to determining that the representative image matches the image of the known legitimate website, the mobile device determines if the unknown website is malicious. The mobile device performs a security action responsive to determining that the website is malicious.
    Type: Grant
    Filed: November 14, 2022
    Date of Patent: January 9, 2024
    Assignee: Zimperium, Inc.
    Inventors: Nicolás Chiaraviglio, Ryan Chazen, Elad Golan, Izhak Kedar, Massimo Dragano, Asaf Peleg
  • Patent number: 11528297
    Abstract: A system and a method are disclosed for detecting a malicious website. In an embodiment, a mobile device detects a URL referencing an unknown website. Responsive to detecting the URL, the mobile device retrieves a representative image of the unknown website. The mobile device determines whether the representative image matches an image of a known legitimate website. Responsive to determining that the representative image matches the image of the known legitimate website, the mobile device determines if the unknown website is malicious. The mobile device performs a security action responsive to determining that the website is malicious.
    Type: Grant
    Filed: December 13, 2019
    Date of Patent: December 13, 2022
    Assignee: Zimperium, Inc.
    Inventors: Nicolás Chiaraviglio, Ryan Chazen, Elad Golan, Izhak Kedar, Massimo Dragano, Asaf Peleg
  • Patent number: 10929532
    Abstract: A trained classifier is received from a server. Static analysis is performed on a mobile application to generate a vector storing values representing the number of times the mobile application calls functions from each of multiple namespaces, and an indication of the permissions the mobile application requests. The received trained classifier is then applied to the generated vector to identify whether the mobile application contains malware. Based on the output of the trained classifier, a security policy is applied.
    Type: Grant
    Filed: September 7, 2018
    Date of Patent: February 23, 2021
    Assignee: Zimperium, Inc.
    Inventor: Simone Margaritelli
  • Patent number: 9503463
    Abstract: A method for a wireless network. The network includes at least a server and a plurality of computer devices wirelessly connected to the server. At least one of the computer devices is under attack by an ‘attacker’ device. The method provides for detection and reporting of the attack as to the location of the attack. The method includes detecting an attack by one of the computer devices, using a zCore module and transmitting an ‘attack report’ to the server. The report includes at least the attack location. The method also includes notifying at least one of the plurality of computer devices and an external computer device that the network is compromised.
    Type: Grant
    Filed: May 13, 2013
    Date of Patent: November 22, 2016
    Assignee: Zimperium, Inc.
    Inventors: Yaniv Karta, Itzhak Avraham
  • Patent number: 9208323
    Abstract: A security system receives attribute samples from one or more devices configured to simulate one or more states (such as attack states). The attribute samples are aggregated, normalized to a common format, and quantized to lower the resolution of the attribute samples. Outlier attribute samples and attribute samples determined to not be correlated to the simulated states are removed to form a pruned set of attribute samples. A set of classifiers is generated based on a first portion of the pruned set of attribute samples, and the set of classifiers is tested based on a second portion of the pruned set of attribute samples. A subset of the classifiers can be provided to a device configured to monitor attributes associated with the subset of classifiers and to identify an attack state based on the monitor attributes.
    Type: Grant
    Filed: January 13, 2014
    Date of Patent: December 8, 2015
    Assignee: Zimperium, Inc.
    Inventors: Yaniv Karta, Itzhak Avraham, Esteban Pellegrino
  • Patent number: 8997231
    Abstract: A method for providing an intrusion prevention system to prevent hacking into files located on enterprise users' endpoint devices functioning as mobile computing platforms. The method includes filtering low-level network packets for each of a plurality of received network packets, offloading the received packets to an inspecting processing module and marking suspicious packets based on at least one of a header and pattern of each of said received packets. The method also includes taking preventive measures by the system to ensure protection of the device and network, taking active steps by the system to block suspicious traffic and disconnecting the current connection by the system, when it detects suspicious traffic.
    Type: Grant
    Filed: April 18, 2013
    Date of Patent: March 31, 2015
    Assignee: Zimperium, Inc.
    Inventors: Yaniv Karta, Itzhak Avraham
  • Publication number: 20140181972
    Abstract: A method for providing an intrusion prevention system to prevent hacking into files located on enterprise users' endpoint devices functioning as mobile computing platforms. The method includes filtering low-level network packets for each of a plurality of received network packets, offloading the received packets to an inspecting processing module and marking suspicious packets based on at least one of a header and pattern of each of said received packets. The method also includes taking preventive measures by the system to ensure protection of the device and network, taking active steps by the system to block suspicious traffic and disconnecting the current connection by the system, when it detects suspicious traffic.
    Type: Application
    Filed: April 18, 2013
    Publication date: June 26, 2014
    Applicant: Zimperium, Inc.
    Inventors: Yaniv Karta, Itzhak Avraham