IP Library Granted Patent US 12,229,264
Granted Patent B2
US 12,229,264 · App. 18/198,861 · Granted Feb 18, 2025

System and method for securing applications through an application-aware runtime agent

Inventors: Chetan Conikee (Santa Clara, CA); Manish Gupta (San Jose, CA); Vlad A Ionescu (Menlo Park, CA); Ignacio del Valle Alles (Asturias, ES)
Assignee: ShiftLeft Inc
G06F21/566G06F21/554G06F21/577H04L63/20H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,229,264
App. No.
18/198,861
Granted
Feb 18, 2025
Kind
B2
Abstract

A system and method for securing an application through an application-aware runtime agent can include: acquiring a code profile, instrumenting the application with a runtime agent according to the code profile, enforcing the runtime agent on the execution of the application, and responding to the runtime agent. Enforcing the runtime agent on the execution of the application can include monitoring the execution flow, which comprises of monitoring the utilization of the controls through the execution of the application; detecting a threat, which comprises identifying a section of the execution flow as a potential security threat; and regulating the execution flow to prevent or ameliorate the security threat. Responding to the runtime agent can include responding to the security threat and providing a user interface that may output runtime agent diagnostics and trigger alerts.

Claims (26)

1. A method for securing an application comprising:

converting a set of code sources of the application to a code profile, which comprises a set of flow graphs and which characterizes controls within the set of code sources;

mapping controls of interest within the code profile by identifying sequences of controls in the set of flow graphs that are associated with detection of a potential security event;

instrumenting the application according to the code profile, wherein instrumenting comprises augmenting the execution of the controls of interest in the application to trigger tracking operations during execution of the application;

during execution of the application, tracking execution flow of the controls of interest through triggered tracking operations, and detecting a security event based at least in part on a detected sequence of execution flow associated with the security event.

2. The method of claim 1 , wherein the controls of interest comprise method calls, datatype activity calls, user defined vulnerabilities, and input and output calls.

3. The method of claim 1 , further comprising, during the execution of the application, monitoring data input.

4. The method of claim 1 , further comprising responding to the security event, which comprises segmenting and classifying a data payload of the execution flow.

5. The method of claim 1 , wherein tracking execution flow of the controls of interest is language agnostic, thereby executable in multiple programming languages.

6. The method of claim 1 , wherein detecting the security event further comprises looking up a section of the execution flow in a security profile dictionary; and responding to the security event further by updating the security profile dictionary.

7. The method of claim 1 , further comprising responding to the security event, which comprises regulating the execution flow and preventing sequential utilization of controls associated with the security event.

8. The method of claim 1 , further comprising responding to the security event, which comprises identifying involved controls within the set of code sources and reporting the involved controls through a user interface.

9. The method of claim 1 , further comprising responding to the security event, which comprises showing portions of the set of code sources that led to detecting the security event.

10. The method of claim 1 , further comprising responding to the security event, which comprises blocking execution flow associated with the security event.

11. The method of claim 1 , further comprising responding to the security event, which comprises modifying firewall settings based on clients involved in the security event.

12. The method of claim 1 , further comprising responding to the security event, which comprises generating a security event notification.

13. The method of claim 1 , wherein detecting the security event comprises identifying a section of the execution flow defined within a security profile dictionary; and responding to the security event by selectively performing at least one of the following:

locating the application controls and external inputs that led to detecting the security event,

preventing sequential utilization of controls associated with the security event,

sending an alert regarding the security event, and

providing a user interface that outputs runtime agent diagnostics and security event alerts and enables user control of the runtime agent.

14. The method of claim 1 , wherein augmenting the execution of the controls of interest in the application to trigger tracking operations further comprises augmenting execution of controls of interest to increment a counter conditional on the execution flow between controls of interest, wherein the counter increments differently depending on if the execution flow satisfies a sequence condition associated with a security event.

15. The method of claim 14 , wherein augmenting the execution of the controls of interest in the application comprises inserting atomic compare and swap instructions at the controls of interest to conditionally increment the counter based on sequence of execution path through instrumented controls.

16. The method of claim 14 , wherein augmenting the execution of the controls of interest in the application comprises inserting jump statements into method calls of the controls of interest, wherein the jump statements conditionally increment the counter based on sequence of execution path through instrumented controls.

17. The method of claim 1 , wherein augmenting the execution of the controls of interest in the application comprises compiling the set of source codes to add the tracking operations to controls of interest.

18. The method of claim 1 , wherein detecting the security event is further based upon, if a sequence of execution flow is associated with a security event, analyzing data payload and detecting the security event based on payload analysis.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2026
From: SHIFTLEFT, INC.
To: HARNESS INC.
Reel/Frame 074196/0845 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2023
From: IONESCU, VLAD A; ALLES, IGNACIO DEL VALLE; CONIKEE, CHETAN; GUPTA, MANISH
To: SHIFTLEFT INC.
Reel/Frame 064598/0602 →
Continuity (4)
Continuation 17178070 · Feb 17, 2021
Continuation 16154151 · Oct 8, 2018
Provisional Application 62569524 · Oct 7, 2017
Related Publication 20230385414A1 · Nov 30, 2023
References Cited (36)
US 5950003A · Kaneshiro et al. · 1999 [cited by applicant]
US 8863288B1 · Savage · 2014 [cited by examiner]
US 9280442B1 · Nicolo · 2016 [cited by applicant]
US 9652358B1 · Spoon · 2017 [cited by applicant]
US 9658835B1 · Venkataramani · 2017 [cited by applicant]
US 10515212B1 · McClintock et al. · 2019 [cited by applicant]
US 10740470B2 · Ionescu et al. · 2020 [cited by applicant]
US 10956574B2 · Conikee et al. · 2021 [cited by applicant]
US 11074362B2 · Conikee et al. · 2021 [cited by applicant]
US 11436337B2 · Ionescu et al. · 2022 [cited by applicant]
US 11514172B2 · Yamaguchi et al. · 2022 [cited by applicant]
US 11657154B2 · Conikee et al. · 2023 [cited by applicant]
US 20070240138A1 · Chess et al. · 2007 [cited by applicant]
US 20080256518A1 · Aoshima et al. · 2008 [cited by applicant]
US 20090307664A1 · Huuck et al. · 2009 [cited by applicant]
US 20100017868A1 · Hao et al. · 2010 [cited by applicant]
US 20100083240A1 · Siman · 2010 [cited by applicant]
US 20100192220A1 · Heizmann et al. · 2010 [cited by applicant]
US 20110083190A1 · Brown et al. · 2011 [cited by applicant]
US 20120102474A1 · Artzi et al. · 2012 [cited by applicant]
US 20130031531A1 · Keynes et al. · 2013 [cited by applicant]
US 20130160130A1 · Mendelev et al. · 2013 [cited by applicant]
US 20140019490A1 · Roy et al. · 2014 [cited by applicant]
US 20140020046A1 · Heitzman · 2014 [cited by applicant]
US 20140143827A1 · Edery et al. · 2014 [cited by applicant]
US 20140282853A1 · Velammal et al. · 2014 [cited by applicant]
US 20160224790A1 · Gupta · 2016 [cited by applicant]
US 20160352769A1 · Bryant et al. · 2016 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170091470A1 · Infante-Lopez · 2017 [cited by applicant]
US 20170206082A1 · Abadi et al. · 2017 [cited by applicant]
US 20170316202A1 · Roichman · 2017 [cited by applicant]
US 20190005163A1 · Farrell et al. · 2019 [cited by applicant]
US 20230009273A1 · Ionescu et al. · 2023 [cited by applicant]
CN 100461132C · 2009 [cited by applicant]
Yamaguchi, Fabian, “Modeling and Discovering Vulnerabilities with Code Property Graphs”, University of Gottingen, Germany, Qualcomm Research Germany, Feb. 2, 2015, “https://www.researchgate.net/publication/263658395_Mod… [cited by applicant]