IP Library › Granted Patent US 12,026,523
Granted Patent B1
US 12,026,523 · App. 18/464,162 · Granted Jul 2, 2024

Dynamically-updatable deep transactional monitoring systems and methods

Inventor: Beth Hunt (Denver, CO)
Assignee: TECH HEIGHTS LLC
G06F9/44521G06F11/302G06F11/3495
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,026,523
App. No.
18/464,162
Granted
Jul 2, 2024
Kind
B1
Abstract

Provided herein are system, method and computer program products for providing dynamically-updatable deep transactional monitoring of running applications in real-time. A method for monitoring a target software application operates by injecting a software engine into a new thread within a target process of the target software application. The method then retrieves a monitoring script and initiates execution of the monitoring script within the software engine. The monitoring script determining the address functions and calls to the functions and inserts a trampoline call within the one or more functions. The trampoline saves the execution state of the target process and calls a corresponding monitoring function that to retrieves data associated with the target process. The method then restoring the execution state of the target process and resumes execution of the target function.

Claims (29)

1. A computer-implemented method of modifying a target application executing in a target process including one or more target threads, the computer-implemented method comprising:

creating a monitoring thread in the target process different than the one or more target threads during runtime of the target process;

starting execution of a software engine in the monitoring thread in the target process, during the runtime of the target process, to execute one or more monitoring scripts during the runtime of the target process, wherein the one or more monitoring scripts executing in the monitoring thread are configured to access memory within the target process and the target application executing in the one or more target threads are configured to access the memory within the target process;

modifying, by execution of the one or more monitoring scripts, executable code of the target application during the runtime of the target process, wherein the modified executable code is configured to generate monitoring data from the runtime of the target process and to store the monitoring data into the memory during the runtime of the target process, wherein the modifying operation includes generating a trampoline in the target process of the target application during runtime of the target process, the trampoline being configured to call monitoring interceptor code in the one or more monitoring scripts at select points during the runtime of the target process and the trampoline saves a state of a memory stack and registers and calls the monitoring interceptor code within the one or more monitoring scripts; and

accessing, by the one or more monitoring scripts in the monitoring thread, the monitoring data in the memory after the monitoring data is stored into the memory.

2. The computer-implemented method of claim 1 , wherein the modifying operation comprises:

modifying one or more instructions in a target function of the target application during runtime of the target process to include instructions that call monitoring interceptor code within the one or more monitoring scripts.

3. The computer-implemented method of claim 1 , further comprising:

updating the one or more monitoring scripts from a source external of the target process without restarting the target process.

4. The computer-implemented method of claim 1 , wherein the one or more monitoring scripts identify one or more functions of the target application to monitor and data from the one or more functions to monitor.

5. The computer-implemented method of claim 1 , wherein the one or more monitoring scripts send monitored data to an agent external of the target process.

6. A computerized system for modifying a target application executing in a target process including one or more target threads, the computerized system comprising:

memory configured to store executable program code and data; and

at least one hardware processor configured to create a monitoring thread in the target process different than the one or more target threads during runtime of the target process, execute a software engine in the monitoring thread in the target process, during the runtime of the target process, to execute one or more monitoring scripts during the runtime of the target process, wherein the one or more monitoring scripts executing in the monitoring thread are configured to access the memory within the target process and the target application executing in the one or more target threads are configured to access the memory within the target process, modify, by execution of the one or more monitoring scripts, executable code of the target application during the runtime of the target process, wherein the modified executable code is configured to generate monitoring data from the runtime of the target process and to store the monitoring data into the memory during the runtime of the target process, and access, by the one or more monitoring scripts in the monitoring thread, the monitoring data in the memory after the monitoring data is stored into the memory, wherein the at least one hardware processor is configured to modify the executable code of a target function of the target application during runtime of the target process by generating a trampoline in the target process, the trampoline being configured to call monitoring interceptor code in the one or more monitoring scripts at select points during the runtime of the target process and the trampoline is configured to save a state of a memory stack and registers and calls the monitoring interceptor code within the one or more monitoring scripts.

7. The computerized system of claim 6 , wherein the at least one hardware processor is configured to modify one or more instructions in a target function of the target application during runtime of the target process to include instructions that call monitoring interceptor code within the one or more monitoring scripts.

8. The computerized system of claim 6 , wherein the at least one hardware processor is further configured to update the one or more monitoring scripts from a source external of the target process without restarting the target process.

9. The computerized system of claim 6 , wherein the one or more monitoring scripts are configured to identify one or more functions of the target application to monitor and data from the one or more functions to monitor.

10. The computerized system of claim 6 , wherein the one or more monitoring scripts are configured to send monitored data to an agent external of the target process.

11. One or more tangible non-transitory processor-readable storage media embodied with instructions for executing on one or more processors and circuits of a computing device a process for modifying a target application executing in a target process including one or more target threads, the process comprising:

creating a monitoring thread in the target process different than the one or more target threads during runtime of the target process;

starting execution of a software engine in the monitoring thread in the target process, during the runtime of the target process, to execute one or more monitoring scripts during the runtime of the target process, wherein the one or more monitoring scripts executing in the monitoring thread are configured to access memory within the target process and the target application executing in the one or more target threads are configured to access the memory within the target process;

modifying, by execution of the one or more monitoring scripts, executable code of the target application during the runtime of the target process, wherein the modified executable code is configured to generate monitoring data from the runtime of the target process and to store the monitoring data into the memory during the runtime of the target process, wherein the modifying operation includes generating a trampoline in the target process of the target application during runtime of the target process, the trampoline being configured to call monitoring interceptor code in the one or more monitoring scripts at select points during the runtime of the target process and the trampoline saves a state of a memory stack and registers and calls the monitoring interceptor code within the one or more monitoring scripts; and

accessing, by the one or more monitoring scripts in the monitoring thread, the monitoring data in the memory after the monitoring data is stored into the memory.

12. The one or more tangible non-transitory processor-readable storage media of claim 11 , further comprising:

modifying one or more instructions in a target function of the target application during runtime of the target process to include instructions that call monitoring interceptor code within the one or more monitoring scripts.

13. The one or more tangible non-transitory processor-readable storage media of claim 11 , further comprising:

updating the one or more monitoring scripts from a source external of the target process without restarting the target process.

14. The one or more tangible non-transitory processor-readable storage media of claim 11 , wherein the one or more monitoring scripts identify one or more functions of the target application to monitor and data from the one or more functions to monitor.

15. The one or more tangible non-transitory processor-readable storage media of claim 11 , wherein the one or more monitoring scripts send monitored data to an agent external of the target process.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2024
From: HUNT, BETH; DAWSON, PHYLLIS
To: SMART ENTERPRISES, INC.
Reel/Frame 067300/0995 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2024
From: SMART ENTERPRISES, INC.
To: TECH HEIGHTS LLC
Reel/Frame 067301/0022 →
Continuity (3)
Continuation 17407034 · Aug 19, 2021
Continuation 16382174 · Apr 11, 2019
Provisional Application 62656308 · Apr 11, 2018