IP Library Granted Patent US 12,547,718
Granted Patent B2
US 12,547,718 · App. 18/634,092 · Granted Feb 10, 2026

Program execution anomaly detection for CyberSecurity

Inventors: Stanislaw Maria Aleksander Lewak (North Palm Beach, FL); Waclaw Tomasz Sierek (Bolechowice, PL); Ian Philip Beeby (New Ross, IE)
Assignee: praedictio.ai, Inc.
G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,718
App. No.
18/634,092
Granted
Feb 10, 2026
Kind
B2
Abstract

A program is executed in a first mode of operation in a controlled environment in accordance with normal operations without malicious behavior. An acceptable behavior model is generated based on a plurality of sequences of events that occur during the normal operation of the program. The acceptable behavior model is indicative of normal behavior of the program that occurs during the normal operation. Then the program is executed in a second mode of operation in an operational environment. An operational sequence of events (determined during the second mode of operation) is compared with the acceptable behavior model. When there is a match between the operational sequence of events and the acceptable behavior model, execution in the second mode of operation continues. When there is not a match between the operational sequence of events and the acceptable behavior model, execution in the second mode of operation is halted.

Claims (62)

1 . A computerized system comprising:

a memory storing executable instructions; and

a processor, coupled to the memory, that performs a method by executing the instructions stored in the memory, the method comprising:

executing, by a computer system, a program in a first mode of operation in a controlled environment in accordance with a normal operation without malicious behavior;

generating, by the computer system, a record of events comprising a plurality of sequences of events that occur during the normal operation of the program;

generating, by the computer system using the record of events, an acceptable behavior model that is indicative of normal behavior of flow control, flow status, or data flow of actions performed by the program that occur during the normal operation without the malicious behavior;

executing, by the computer system, the program in a second mode of operation after the program has been deployed in runtime in a non-isolated, real-world, operational network environment;

determining, by the computer system, an operational sequence of events of the program during execution of the program in the second mode of operation, the operational sequence of events including a current action;

comparing, by the computer system, the operational sequence of events with the acceptable behavior model;

when the comparing step results in a match between the operational sequence of events and the acceptable behavior model, performing the current action in the second mode of operation; and

when the comparing step does not result in the match between the operational sequence of events and the acceptable behavior model, not performing the current action and generating an alert to stop the executing of the program.

2 . The computerized system of claim 1 , wherein:

each sequence of events of the plurality of sequences of events comprises a plurality of events that occur during the normal operation of the program.

3 . The computerized system of claim 1 , wherein:

the program is written in an interpreted language; and

the method further comprises;

instrumenting code of the program to include instrumented code; and

interpreting the program by a code interpreter to generate a first portion of executable code that is based on the code of the program and a second portion of executable code that is based on the instrumented code.

4 . The computerized system of claim 3 , wherein:

the executing of the program in the first mode of operation and in the second mode of operation is performed after interpreting the program by the code interpreter; and

the generating of the record of events is performed by executing the second portion of executable code.

5 . The computerized system of claim 3 , wherein:

the instrumenting of the code of the program to include the instrumented code is performed before the program is provided to the code interpreter.

6 . The computerized system of claim 3 , wherein:

the instrumenting of the code of the program to include the instrumented code is performed by the code interpreter while interpreting the code of the program.

7 . The computerized system of claim 1 , further comprising:

instrumenting, by the computer system using a compiler, code of the program, the program containing instrumented executable code;

wherein:

the executing of the program in the first mode of operation results in the generating of the record of events in accordance with instrumentation of the instrumented executable code of the program.

8 . The computerized system of claim 1 , wherein:

the executing of the program in the first mode of operation is performed by a first processor of the computer system; and

the generating of the record of events is performed by a second processor separate from the first processor.

9 . The computerized system of claim 1 , wherein:

the executing of the program in the second mode of operation is performed by a first processor of the computer system; and

the determining of the operational sequence of events is performed by a second processor of the computer system separate from the first processor.

10 . The computerized system of claim 1 , wherein:

the acceptable behavior model is an artificial intelligence model trained on the plurality of sequences of events, which are known to occur during the normal operation of the program without the malicious behavior.

11 . A computerized system comprising:

a memory storing executable instructions; and

a processor, coupled to the memory, that performs a method by executing the instructions stored in the memory, the method comprising:

executing, by a computer system, a program in a first mode of operation in a controlled environment in accordance with a normal operation without malicious behavior;

generating, by the computer system, a record of events comprising a plurality of sequences of events that occur during the normal operation of the program; and

generating, by the computer system using the record of events, an acceptable behavior model that is indicative of normal behavior of flow control, flow status, or data flow of actions performed by the program that occur during the normal operation without the malicious behavior;

wherein:

the acceptable behavior model is configured to be used to prevent execution of a current action of the program in a second mode of operation after the program has been deployed in runtime in a non-isolated, real-world, operational network environment when it is determined that the current action of the program is part of an operational sequence of events that does not match the acceptable behavior model.

12 . The computerized system of claim 11 , wherein:

each sequence of events of the plurality of sequences of events comprises a plurality of events that occur during the normal operation of the program.

13 . The computerized system of claim 11 , wherein:

the program is written in an interpreted language; and

the method further comprises instrumenting code of the program to include instrumented code;

the method further comprises interpreting the program by a code interpreter to generate a first portion of executable code that is based on the code of the program and a second portion of executable code that is based on the instrumented code;

the executing of the program in the first mode of operation and in the second mode of operation is performed after interpreting the program by the code interpreter; and

the generating of the record of events is performed by executing the second portion of executable code.

14 . The computerized system of claim 11 , further comprising:

instrumenting, by the computer system using a compiler, code of the program, the program containing instrumented executable code;

wherein:

the executing of the program in the first mode of operation results in the generating of the record of events in accordance with instrumentation of the instrumented executable code of the program.

15 . The computerized system of claim 11 , wherein:

the executing of the program in the first mode of operation is performed by a first processor of the computer system; and

the generating of the record of events is performed by a second processor of the computer system separate from the first processor.

16 . The computerized system of claim 11 , wherein:

the acceptable behavior model is an artificial intelligence model trained on the plurality of sequences of events, which are known to occur during the normal operation of the program without the malicious behavior.

Assignments (2)
CHANGE OF NAME Recorded Dec 12, 2025
From: CYBERSENTRY.AI, INC.
To: PRAEDICTIO.AI, INC.
Reel/Frame 073857/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2024
From: LEWAK, STANISLAW MARIA ALEKSANDER; SIEREK, WACLAW TOMASZ; BEEBY, IAN PHILIP
To: CYBERSENTRY.AI, INC.
Reel/Frame 067115/0990 →
Continuity (3)
Continuation 18485049 · Oct 11, 2023
Provisional Application 63415852 · Oct 13, 2022
Related Publication 20240273205A1 · Aug 15, 2024
References Cited (27)
US 9942268B1 · Danileiko · 2018 [cited by applicant]
US 10691796B1 · Stolte et al. · 2020 [cited by applicant]
US 11082438B2 · Peinador et al. · 2021 [cited by applicant]
US 11106799B2 · Keromytis et al. · 2021 [cited by applicant]
US 20130247180A1 · Camp · 2013 [cited by applicant]
US 20140165140A1 · Singla et al. · 2014 [cited by applicant]
US 20150309813A1 · Patel · 2015 [cited by applicant]
US 20170017789A1 · Daymont · 2017 [cited by applicant]
US 20170293477A1 · Takata et al. · 2017 [cited by applicant]
US 20180024911A1 · Kruszewski et al. · 2018 [cited by applicant]
US 20180107821A1 · Eshkenazi et al. · 2018 [cited by applicant]
US 20210288983A1 · Tambuluri et al. · 2021 [cited by applicant]
US 20220058077A1 · Stolfo et al. · 2022 [cited by applicant]
US 20220092179A1 · Zhang · 2022 [cited by examiner]
EP 2893447A2 · 2015 [cited by applicant]
EP 3314437A · 2018 [cited by applicant]
WO 2019066099A1 · 2019 [cited by applicant]
WO 2020180887A1 · 2020 [cited by applicant]
WO 2023067665A1 · 2023 [cited by applicant]
International Search Report and Written Opinion dated Dec. 28, 2023 for PCT Patent Application No. PCT/IB2023/060256. [cited by applicant]
Notice of Allowance and Fees dated Apr. 2, 2024 for U.S. Appl. No. 18/485,049. [cited by applicant]
Office Action dated Dec. 4, 2023 for U.S. Appl. No. 18/485,049. [cited by applicant]
Abadi et al., “Control-Flow Integrity: Principles, Implementations, and Applications”. In: ACM Transactions on Information and System Security (TISSEC) 13.1, Nov. 2009. doi: 10.1145/1609956.1609960. url: https://users.s… [cited by applicant]
Jacobs et al. “System Call Interposition Without Compromise”. In: 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). Jun. 2024, pp. 183-194. doi: 10.1109/DSN58291.2024.00030. [cited by applicant]
Nyman, “Toward Hardware-assisted Run-time Protection”. Doctoral dissertation. Aalto University, 2020. url: http://urn.fi/URN:ISBN:978-952-64-0065-5 (visited on May 22, 2025). [cited by applicant]
Van Der Veen et al. “Practical Context-Sensitive CFI”. In: Proceedings of the 22nd ACM SIGSAC Conference. Oct. 2015. doi: 10.1145/2810103.2813673. url: https://www.researchgate.net/publication/301419772_Practical_Contex… [cited by applicant]
Yasukata et al. “zpoline: a system call hook mechanism based on binary rewriting”. In: 2023 USENIX Annual Technical Conference (USENIX ATC 23). Boston, MA: USENIX Association, Jul. 2023, pp. 293-300. isbn: 978-1-939133-… [cited by applicant]