IP Library Granted Patent US 12,578,938
Granted Patent B2
US 12,578,938 · App. 18/043,239 · Granted Mar 17, 2026

Exploit prevention based on generation of random chaotic execution context

Inventor: Avihay Cohen (Tiberias, IL)
Assignee: SERAPHIC ALGORITHMS LTD
G06F8/41
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,578,938
App. No.
18/043,239
Granted
Mar 17, 2026
Kind
B2
Abstract

A non-transitory computer readable medium containing instructions that when executed by at least one processor cause the at least one processor to perform cybersecurity operations. The cybersecurity operations may involve determining that an operating system has initiated a computing process, and replacing the computing process with a code configured to create a map representing a structure of an original binary image associated with the replaced computing process. A modified execution context may be generated for the computing process and the original binary image may be recompiled into an execution binary image compatible with the modified execution context. The computing process may then be executed using the execution binary image and the map.

Claims (36)

1 . A non-transitory computer readable medium containing instructions that when executed by at least one processor cause the at least one processor to perform cybersecurity operations comprising:

determining that an operating system has initiated a computing process;

replacing the computing process with an executable code configured to create a map representing a structure of an original binary image associated with the replaced computing process;

generating a modified execution context for the replaced computing process, wherein at least one of a datum, an instruction, a register, or a location is replaced with a corresponding datum, instruction, register, and location associated with the modified execution context;

recompiling the original binary image into an execution binary image that includes the map and is compatible with the modified execution context; and

executing the replaced computing process using the execution binary image and the map.

2 . The non-transitory computer readable medium of claim 1 , wherein the modified execution context includes an emulated central processing unit (CPU).

3 . The non-transitory computer readable medium of claim 2 , wherein the modified execution context includes an instruction set associated with the emulated CPU.

4 . The non-transitory computer readable medium of claim 3 , wherein the instruction set associated with the emulated CPU is non-native to a hardware processor on which the replaced computing process is run.

5 . The non-transitory computer readable medium of claim 1 , wherein the modified execution context includes randomized registers.

6 . The non-transitory computer readable medium of claim 1 , wherein the modified execution context includes randomized memory locations.

7 . The non-transitory computer readable medium of claim 1 , wherein the modified execution context exhibits non-predictability.

8 . The computer readable medium of claim 1 , wherein the modified execution context includes random padding of random segments in the code.

9 . The computer readable medium of claim 1 , wherein the modified execution context includes at least one randomized property of at least one Application Programming Interface.

10 . The computer readable medium of claim 1 , wherein recompiling the original binary image comprises using the map for maintaining compatibility between the execution binary image and the modified execution context.

11 . A method for performing cybersecurity operations comprising:

determining that an operating system has initiated a computing process;

replacing the computing process with an executable configured to obtain a map representing a structure of an original binary image associated with the replaced computing process;

obtaining a modified execution context generated for the replaced computing process, wherein at least one of a datum, an instruction, a register, or a location is replaced with a corresponding datum, instruction, register, and location associated with the modified execution context;

recompiling the original binary image into an execution binary image that includes the map and is compatible with the modified execution context; and

executing the replaced computing process using the execution binary image and the map.

12 . The method of claim 11 , wherein the modified execution context includes an emulated central processing unit (CPU).

13 . The method of claim 12 , wherein the modified execution context includes an instruction set associated with the emulated CPU, wherein the instruction set is non-native to a hardware processor on which the replaced computing process is run.

14 . The method of claim 11 , wherein the modified execution context includes at least one of randomized registers or randomized memory locations.

15 . The method of claim 11 , wherein the modified execution context exhibits non-predictability.

16 . A system for performing cybersecurity operations, comprising:

at least one processor configured to:

determine that an operating system has initiated a computing process;

replace the computing process with an executable configured to create a map representing a structure of an original binary image associated with the replaced computing process;

generate a modified execution context for the replaced computing process, wherein at least one of a datum, an instruction, a register, or a location is replaced with a corresponding datum, instruction, register, and location associated with the modified execution context;

recompile the original binary image into an execution binary image that includes the map and is compatible with the modified execution context; and

execute the replaced computing process using the execution binary image and the map.

17 . The system of claim 16 , wherein the modified execution context includes an emulated central processing unit (CPU).

18 . The system of claim 17 , wherein the modified execution context includes an instruction set associated with the emulated CPU wherein the instruction set is non-native to the at least one processor.

19 . The system of claim 16 , wherein the modified execution context includes at least one of randomized registers or randomized memory locations.

20 . The system of claim 16 , wherein the modified execution context exhibits non-predictability.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jun 25, 2026
From: HSBC BANK PLC
To: SERAPHIC ALGORITHMS LTD
Reel/Frame 075079/0275 →
SECURITY INTEREST Recorded May 12, 2025
From: SERAPHIC ALGORITHMS LTD
To: HSBC BANK PLC
Reel/Frame 071088/0637 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2023
From: COHEN, AVIHAY
To: SERAPHIC ALGORITHMS LTD.
Reel/Frame 062813/0934 →
Continuity (3)
Continuation In Part PCTIL2021051063 · Aug 31, 2021
Provisional Application 63072289 · Aug 31, 2020
Related Publication 20250077198A1 · Mar 6, 2025
References Cited (11)
US 20150039864A1 · Tobin · 2015 [cited by applicant]
US 20150040223A1 · Tobin · 2015 [cited by applicant]
US 20150047049A1 · Panchenko et al. · 2015 [cited by applicant]
US 20160171212A1 · Majumdar et al. · 2016 [cited by applicant]
US 20180075238A1 · Ferrie · 2018 [cited by applicant]
US 20180260559A1 · Jarrous et al. · 2018 [cited by applicant]
US 20200073826A1 · Tsirkin · 2020 [cited by examiner]
International Search Report and Written Opinion in Application No. PCT/IB22/51688 dated May 11, 2022 (14 pages). [cited by applicant]
Larsen et al., SoK: Automated Software Diversity. In 2014 IEEE Symposium on Security and Privacy (pp. 276-291). IEEE, May 2014 [retrieved on Apr. 17, 2022]. Retrieved from the Internet: <https://cse.usf.edu/˜xou/sec15/s… [cited by applicant]
International Search Report and Written Opinion in Application No. PCT/IL2021/051063 dated Nov. 15, 2021 (8 pages). [cited by applicant]
Extended European Search Report in Europen Patent Application No. 228673710.4 dated Apr. 3, 2025 (8 pages). [cited by applicant]