IP Library › Granted Patent US 12,158,960
Granted Patent B2
US 12,158,960 · App. 18/317,807 · Granted Dec 3, 2024

Applying constraints models for application layer security

Inventor: Judson Powers (Eden Prairie, MN)
Assignee: Architecture Technology Corporation
G06F21/577G06N20/00G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,158,960
App. No.
18/317,807
Granted
Dec 3, 2024
Kind
B2
Abstract

A computer-implemented method of securing vulnerabilities in a program, the method including receiving, by a computer, state information generated by an executed application program, training, by the computer, a constraints model based on the state information, generating, by the computer, one or more constraints with the constraints model, each of the one or more constraints describing an execution constraint for executing the application program, wherein the execution constraint enforces an intended operation of the application program, and applying, by the computer, the one or more constraints to the application program.

Claims (31)

1. A computer-implemented method of securing vulnerabilities in a program, the method comprising:

receiving, by a computer, state information generated by an application program during execution of the application program;

generating, by a computer, expected state information by applying a constraints model on the state information;

generating, by the computer, one or more constraints according to the constraints model and based on a difference between the state information and the expected state information, the one or more constraints containing an execution constraint including a machine-readable instruction configured to prevent the application program from instructing a machine to deviate from a normal operation; and

applying, by the computer, the one or more constraints to the application program.

2. The computer-implemented method of claim 1 , wherein applying the one or more constraints to the application program includes generating executable code for a processing device running the application program and transmitting the executable code to the processing device.

3. The computer-implemented method of claim 1 , wherein the state information results from business logic of the application program.

4. The computer-implemented method of claim 3 , wherein the state information comprises internal variables of the application program.

5. The computer-implemented method of claim 1 , further comprising training, by the computer, the constraints model with normal state information from the executed application program under normal operation.

6. The computer-implemented method of claim 1 , wherein the one or more constraints address security vulnerabilities in a business logic of an application layer of the application program.

7. The computer-implemented method of claim 1 , wherein the one or more constraints include at least one of an allowable range for an internal variable, an allowable state transition sequence, or an expected state dependent internal variable value.

8. A system for determining security vulnerabilities associated with an application program, the system comprising:

a non-transitory computer-readable storage medium having instructions stored thereon; and

a processor configured to execute the instructions to:

receive state information generated by an application program during execution of the application program;

generate expected state information by applying a constraints model on the state information;

generate one or more constraints according to the constraints model and based on a difference between the state information and the expected state information, the one or more constraints containing an execution constraint including a machine-readable instruction configured to prevent the application program from instructing a machine to deviate from a normal operation; and

apply the one or more constraints to the application program.

9. The system of claim 8 , wherein the state information results from business logic of the application program.

10. The system of claim 9 , wherein the state information comprises internal variables of the application program.

11. The system of claim 8 , wherein the processor is further configured to train the constraints model with normal state information from the executed application program under normal operation.

12. The system of claim 8 , wherein the one or more constraints address security vulnerabilities in a business logic of an application layer of the application program.

13. The system of claim 8 , wherein the one or more constraints include at least one of an allowable range for an internal variable, an allowable state transition sequence, or an expected state dependent internal variable value.

14. The system of claim 8 , wherein the processor is further configured to apply the one or more constraints to the application program.

15. The system of claim 14 , wherein applying the one or more constraints to the application program includes generating executable code for a processing device running the application program and transmitting the executable code to the processing device.

16. A non-transitory computer-readable storage medium having instructions stored thereon that, when executed by a processor, cause the processor to:

receive state information generated by an application program during execution of the application program;

generate expected state information by applying a constraints model on the state information;

generate one or more constraints according to the constraints model and based on a difference between the state information and the expected state information, the one or more constraints containing an execution constraint including a machine-readable instruction configured to prevent the application program from instructing a machine to deviate from a normal operation; and

apply the one or more constraints to the application program.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the instructions further cause the processor to train the constraints model with normal state information from the executed application program under normal operation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2023
From: POWERS, JUDSON
To: ARCHITECTURE TECHNOLOGY CORPORATION
Reel/Frame 063647/0453 →
Continuity (2)
Continuation 16891559 · Jun 3, 2020
Related Publication 20230281322A1 · Sep 7, 2023