IP Library › Granted Patent US 12,141,301
Granted Patent B2
US 12,141,301 · App. 18/559,480 · Granted Nov 12, 2024

Using entropy to prevent inclusion of payload data in code execution log data

Inventor: Jordi Mola (Bellevue, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/62G06F11/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,141,301
App. No.
18/559,480
Granted
Nov 12, 2024
Kind
B2
Abstract

Using entropy to prevent inclusion of pay load data in code execution log data. Embodiments determine that a payload data item associated with code execution log data has entropy exceeding a defined entropy threshold and identify a particular executable code that interacted with the payload data item. Embodiments then take a preventative action that excludes the pay load data item from inclusion with a record of execution of the particular executable code. Examples of preventative actions include preventing the pay load data item from being exported from the computer system, preventing the pay load data item from being included in the code execution log data, and adding the payload data item to a block list in reference to the particular executable code.

Claims (20)

1. A method, implemented at a computer system that includes a processor, for preventing inclusion of payload data in code execution log data, the method comprising:

determining that a payload data item associated with code execution log data has entropy exceeding a defined entropy threshold;

identifying a particular executable code that interacted with the payload data item; and

taking a preventative action that excludes the payload data item from inclusion with a record of execution of the particular executable code.

2. The method of claim 1 , wherein determining that the payload data item has entropy exceeding the defined entropy threshold comprises determining that the payload data item has intrinsic entropy exceeding the defined entropy threshold.

3. The method of claim 2 , wherein determining that the payload data item has intrinsic entropy exceeding the defined entropy threshold comprises at least one of:

computing a ratio of a number of bits of entropy in the payload data item versus a total number of bits in the payload data item; or

computing a compressibility of the payload data item.

4. The method of claim 1 , wherein determining that the payload data item has entropy exceeding the defined entropy threshold comprises determining that the payload data item has contextual entropy exceeding the defined entropy threshold, the contextual entropy being relative to a plurality related payload data items identified from a plurality of related code execution logs.

5. The method of claim 1 , wherein identifying the particular executable code that interacted with the payload data item comprises identifying executable code that consumed the payload data item.

6. The method of claim 1 , wherein identifying the particular executable code that interacted with the payload data item comprises identifying executable code that generated the payload data item.

7. The method of claim 1 , wherein identifying the particular executable code that interacted with the payload data item comprises identifying a particular executable instruction.

8. The method of claim 1 , wherein identifying the particular executable code that interacted with the payload data item comprises identifying a particular function.

9. The method of claim 1 , wherein the preventative action comprises preventing the payload data item from being exported from the computer system.

10. The method of claim 1 , wherein the preventative action comprises preventing the payload data item from being included in the code execution log data.

11. The method of claim 10 , wherein preventing the payload data item from being included in the code execution log data comprises replacing the payload data item in the code execution log data with one or more of (i) substitute data, (ii) one or more constraints on the payload data, or (iii) a code flow override for the particular executable code.

12. The method of claim 1 , wherein the preventative action comprises adding the payload data item to a block list in reference to the particular executable code, the block list being structured to prevent the payload data item from being included in a subsequently generated code execution log data.

13. The method of claim 1 , wherein determining that the payload data item has entropy exceeding the defined entropy threshold comprises identifying the payload data item from a block list based at least on a reference to the particular executable code.

14. The method of claim 1 , wherein determining that the payload data item has entropy exceeding the defined entropy threshold comprises identifying the payload data item during a post-processing of the code execution log data.

15. The method of claim 1 , wherein the method is applied transitively to exclude an additional instance of payload data item, or derivative thereof, from inclusion in another record of execution another executable code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2023
From: MOLA, JORDI
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 065487/0198 →
Priority Claims (1)
LU 500189 · May 21, 2021 · national
Continuity (1)
Related Publication 20240241974A1 · Jul 18, 2024