IP Library › Granted Patent US 12,340,002
Granted Patent B2
US 12,340,002 · App. 18/032,110 · Granted Jun 24, 2025

Monitoring range determination device, monitoring range determination method, and computer readable medium

Inventors: Yuto Hayaki (Tokyo, JP); Norio Yamagaki (Tokyo, JP)
Assignee: NEC CORPORATION
G06F21/64G06F21/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,340,002
App. No.
18/032,110
Granted
Jun 24, 2025
Kind
B2
Abstract

A device includes: an input/output unit configured to receive input of the binary of the software to be monitored in which a tamper detection feature and tamper detection feature calling functions are embedded; a CFG (control flow graph) generation unit configured to generate a CFG based on the binary; and an allowed list creation unit configured to determine the monitoring range for the tamper detection feature calling functions based on the CFG. The allowed list creation unit sequentially selects the tamper detection feature calling functions on the CFG, adds a node to the monitoring range for the selected tamper detection feature calling functions according to a predetermined rule, searches for the tamper detection feature calling function to be be executed next to the added node according to the predetermined rule, and adds the found tamper detection feature calling function to the monitoring range for the selected tamper detection feature calling functions.

Claims (31)

1. A monitoring range determination device configured to determine a monitoring range for tamper detection feature calling functions that are embedded with a tamper detection feature in software to be monitored, the monitoring range determination device comprising:

at least one memory storing instructions; and

at least one processor configured to execute the instructions to:

receive input of a binary of the software in which the tamper detection feature and the tamper detection feature calling functions are embedded;

generate a control flow graph (CFG) based on the binary; and

determine the monitoring range for the tamper detection feature calling functions based on the CFG,

wherein the at least one processor is further configured to execute the instructions to

sequentially select the tamper detection feature calling functions on the CFG;

add a node to the monitoring range for the selected tamper detection feature calling functions according to a predetermined rule; and

search for the tamper detection feature calling function that is to be executed next to the added node according to the predetermined rule, and add the tamper detection feature calling function that is found to the monitoring range for the selected tamper detection feature calling functions,

wherein the predetermined rule is a rule that traces nodes that do not contain the tamper detection feature calling functions among all descendant nodes of a node containing the selected tamper detection feature calling functions, and adds the range from the node containing the selected tamper detection feature calling functions to a node immediately before the next node containing the tamper detection feature calling functions to the monitoring range for the selected tamper detection feature calling functions.

2. The monitoring range determination device according to claim 1 , wherein upon finding a node that has not been added to the monitoring range for any of the tamper detection feature calling functions on the CFG before finding the tamper detection feature calling function that is to be executed next after the node added according to the predetermined rule, the at least one processor is further configured to execute the instructions to add the node that has been found to the monitoring range for the selected tamper detection feature calling functions.

3. The monitoring range determination device according to claim 1 , wherein the tamper detection feature is an allowed list type tamper detection feature created as a list of hash values of the monitoring range for the tamper detection feature calling functions.

4. A monitoring range determination method performed by a monitoring range determination device configured to determine a monitoring range for tamper detection feature calling functions that are embedded with a tamper detection feature in a software to be monitored, the monitoring range determination method comprising:

inputting a binary of the software in which the tamper detection feature and the tamper detection feature calling functions are embedded;

generating a control flow graph (CFG) based on the binary; and

a monitoring range determination step of determining the monitoring range for the tamper detection feature calling functions based on the CFG,

wherein the monitoring range determination method includes

sequentially selecting the tamper detection feature calling functions on the CFG;

adding a node to the monitoring range for the selected tamper detection feature calling functions according to a predetermined rule; and

searching for the tamper detection feature calling function that is to be executed next to the added node according to the predetermined rule, and adding the tamper detection feature calling function that is found to the monitoring range for the selected tamper detection feature calling functions,

wherein the predetermined rule is a rule that traces nodes that do not contain the tamper detection feature calling functions among all descendant nodes of a node containing the selected tamper detection feature calling functions, and adds the range from the node containing the selected tamper detection feature calling functions to a node immediately before the next node containing the tamper detection feature calling functions to the monitoring range for the selected tamper detection feature calling functions.

5. A non-transitory computer readable medium storing a program that executable by a computer to perform processing of determining a monitoring range for tamper detection feature calling functions that are embedded with a tamper detection feature in a software to be monitored, the processing comprising:

inputting a binary of the software in which the tamper detection feature and the tamper detection feature calling functions are embedded;

generating a control flow graph (CFG) based on the binary; and

a monitoring range determination step of determining the monitoring range for the tamper detection feature calling functions based on the CFG,

wherein the monitoring range determination method includes

sequentially selecting the tamper detection feature calling functions on the CFG;

adding a node to the monitoring range for the selected tamper detection feature calling functions according to a predetermined rule; and

searching for the tamper detection feature calling function that is to be executed next to the added node according to the predetermined rule, and adding the tamper detection feature calling function that is found to the monitoring range for the selected tamper detection feature calling functions,

wherein the predetermined rule is a rule that traces nodes that do not contain the tamper detection feature calling functions among all descendant nodes of a node containing the selected tamper detection feature calling functions, and adds the range from the node containing the selected tamper detection feature calling functions to a node immediately before the next node containing the tamper detection feature calling functions to the monitoring range for the selected tamper detection feature calling functions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2023
From: HAYAKI, YUTO; YAMAGAKI, NORIO
To: NEC CORPORATION
Reel/Frame 063330/0477 →
Continuity (1)
Related Publication 20230401339A1 · Dec 14, 2023
References Cited (15)
US 6829710B1 · Venkatesan · 2004 [cited by examiner]
US 20030188231A1 · Cronce · 2003 [cited by examiner]
US 20080184041A1 · Jakubowski · 2008 [cited by examiner]
US 20150240531A1 · Blust · 2015 [cited by examiner]
US 20150269805A1 · Korala · 2015 [cited by examiner]
US 20150278511A1 · Foley · 2015 [cited by examiner]
US 20170024983A1 · Reeves · 2017 [cited by examiner]
US 20170249456A1 · Fu · 2017 [cited by examiner]
US 20180276374A1 · Baldwin · 2018 [cited by examiner]
US 20200042695A1 · Kanei · 2020 [cited by examiner]
WO 2018150619A1 · 2018 [cited by applicant]
International Search Report for PCT Application No. PCT/JP2020/040339, mailed on Jan. 19, 2021. [cited by applicant]
Kobayashi, Toshiki et al., “SAFES: Sand-boxed Architecture for Frequent Environment Self-measurement”, SysTEX 18: Proceedings of the 3rd Workshop on System Software for Trusted Execution, Oct. 15, 2018, pp. 1-5. [cited by applicant]
Hayaki, Yuto, “Proposal of proof of trust by tampering detection system for IoT devices”, SCIS 2020, The Institute of Electronics, Information and Communication Engineers, Jan. 21, 2020, 2D1-4, pp. 1-6 [cited by applicant]
NEC Digital Platform Operations, “Lightweight program tampering detection development kit for detecting unlawful manipulation of IoT devices”, C&C User Forum & EXPO, Oct. 2019, pp. 1-2. [cited by applicant]