IP Library › Patent Application 16382174
Patent Application
App. No. 16/382,174

Dynamically-Updatable Deep Transactional Monitoring Systems and Methods

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/382,174
Abstract

Provided herein are system, method and computer program products for providing dynamically-updatable deep transactional monitoring of running applications in real-time. A method for monitoring a target software application operates by injecting a software engine into a new thread within a target process of the target software application. The method then retrieves a monitoring script and initiates execution of the monitoring script within the software engine. The monitoring script determining the address functions and calls to the functions and inserts a trampoline call within the one or more functions. The trampoline saves the execution state of the target process and calls a corresponding monitoring function that to retrieves data associated with the target process. The method then restoring the execution state of the target process and resumes execution of the target function.

Claims (63)

1 . A computer-implemented method for monitoring a target software application, the method comprising:

injecting a software engine into a new thread within a target process of the target software application;

retrieving a monitoring script; and

initiating execution of the monitoring script within the software engine, the monitoring script configured to perform steps comprising:

determining the address of one or more functions and one or more calls to the one or more functions,

inserting a trampoline call within the one or more functions, the trampoline saving the execution state of the target process and calling a corresponding monitoring function, wherein the monitoring function is configured to retrieve one or more data values associated with the target process,

restoring the execution state of the target process, and

resuming execution of the target function.

2 . The method of claim 1 , wherein the injecting, receiving, and initiating execution steps are performed by a separate agent process within an environment of the target software.

3 . The method of claim 1 , wherein the injecting, receiving, and initiating execution steps are performed by an agent running within the target process.

4 . The method of claim 1 , the method further comprising:

injecting the software engine into a second new thread within a second target process of the target software application; and

initiating execution of the same or a different monitoring script within the software engine in the second new thread.

5 . The method of claim 1 , further comprising:

receiving a second monitoring script through the communications channel; and

initiating execution of the second monitoring script within the software engine.

6 . The method of claim 1 , further comprising:

determining whether a new monitoring script is available or an existing monitoring script has been modified;

retrieving the new or modified monitoring script; and

initiating execution of the new or modified monitoring script.

7 . The method of claim 1 , wherein the software engine accesses or modifies computer memory locations, execution stack, registers, and threads within the target process.

8 . The method of claim 1 , wherein the retrieving the monitoring script comprises receiving the monitoring script through a communications channel.

9 . The method of claim 8 , wherein the communications channel comprises at least one of a secure shell (SSH) tunnel connection or a Transport Control Processes (TCP) connection.

10 . The method of claim 1 , wherein the software engine comprises at least one of a Google V8 engine or a Duktape engine.

11 . The method of claim 1 , wherein the monitoring script is configured to further perform the steps of:

finding a target application function in the target process;

initiating execution of the target application function; and

retrieving data resulting from the execution of the function.

12 . The method of claim 1 , wherein the monitoring script is a Javascript script.

13 . The method of claim 1 , wherein the at least one or more data values comprises at least one of a value of a process, application, or function variable, a value of a memory location, a function return value or input value, or a timestamp.

14 . A computer-implemented method for monitoring a target software application, the method comprising:

injecting a software engine into a new thread within a target process of the target software application;

retrieving a monitoring script;

initiating execution of the monitoring script within the software engine, the monitoring script configured to perform steps comprising:

intercepting a function call of the target process,

splitting a plurality of instructions of the function into a plurality of blocks,

wrapping each of the instructions in instrumentation,

performing a call back to a monitoring script at the end of each of the plurality of blocks, wherein the monitoring script is configured to store one or more data values associated with the target process.

15 . The method of claim 12 , wherein each of the plurality of blocks comprises a sequence of instructions with no branches-in except to the entry of the block and no branches-out except at the exit of the block.

16 . The method of claim 12 , the method further comprising:

injecting the software engine into a second new thread within a second target process of the target software application; and

initiating execution of the monitoring script within the software engine in the second new thread.

17 . The method of claim 12 , further comprising:

receiving a second monitoring script through the communications channel; and

initiating execution of the second monitoring script within the software engine.

18 . A tangible non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, causes the at least one computing device to perform operations comprising:

injecting a software engine into a new thread within a target process of the target software application;

receiving a monitoring script; and

initiating execution of the monitoring script within the software engine, the monitoring script configured to perform steps comprising:

determining the address of one or more functions and one or more calls to the one or more functions,

inserting a trampoline call within the one or more functions, the trampoline saving the execution state of the target process and calling a corresponding monitoring function, wherein the monitoring function is configured to retrieve one or more data values associated with the target process,

restoring the execution state of the target process, and

resuming execution of the target function.

19 . A system, comprising:

a memory; and

at least one processor coupled to the memory and configured to:

inject a software engine into a new thread within a target process of the target software application;

receive a monitoring script; and

initiate execution of the monitoring script within the software engine, the monitoring script configured to perform steps comprising:

determining the address of one or more functions and one or more calls to the one or more functions,

inserting a trampoline call within the one or more functions, the trampoline saving the execution state of the target process and calling a corresponding monitoring function, wherein the monitoring function is configured to retrieve one or more data values associated with the target process,

restoring the execution state of the target process, and

resuming execution of the target function.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2023
From: SMART ENTERPRISES, INC.
To: TECH HEIGHTS LLC
Reel/Frame 064817/0442 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2020
From: DAWSON, PHYLLIS
To: SMART ENTERPRISES, INC.
Reel/Frame 053303/0527 →