IP Library Granted Patent US 12,045,346
Granted Patent B2
US 12,045,346 · App. 18/497,019 · Granted Jul 23, 2024

Systems and methods for causing nonpredictable environment states for exploit prevention and malicious code neutralization for javascript-enabled applications

Inventor: Avihay Cohen (Tel-Aviv, IL)
Assignee: SERAPHIC ALGORITHMS, LTD.
G06F21/554G06F21/128G06F21/54G06F9/45529G06F9/54G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,045,346
App. No.
18/497,019
Granted
Jul 23, 2024
Kind
B2
Abstract

Systems, methods, and computer-readable media for cybersecurity are disclosed. The systems and methods may involve receiving, by an application capable of JavaScript execution, code for execution; executing, before execution of the received code, an intercepting code, wherein the intercepting code is configured to intercept at least one application programming interface (API) invocation by the received code; intercepting, by the intercepting code, an API invocation by the received code; determining that the intercepted API invocation results in a manipulation of a backing store object; and modifying an execution of the intercepted API invocation, wherein the modified execution results in a nonpredictable environment state.

Claims (60)

1. A cyber security system comprising:

at least one processor configured to:

receive, by an application capable of JavaScript execution, code for execution;

execute, before execution of the received code, an intercepting code, wherein the intercepting code is configured to intercept at least one application programming interface (API) invocation by the received code;

intercept, by the intercepting code, an API invocation by the received code;

determine that the intercepted API invocation is configured to result in a manipulation of a backing store object; and

modify an execution of the intercepted API invocation, wherein the modified execution changes an effect of the intercepted API invocation, and wherein modifying the execution of the intercepted API invocation includes at least one of:

padding input data associated with the API invocation;

encoding input data associated with the API invocation;

manipulating input data associated with the API invocation;

splitting, into multiple execution contexts, input data associated with the API invocation;

manipulating an object shape associated with the API invocation;

manipulating an object structure associated with the API invocation;

causing an object to reside in an unpredictable memory location;

causing an object to reside in multiple execution contexts; or

causing an object to have random varying properties.

2. The cyber security system of claim 1 , wherein the modified execution results in a nonpredictable environment state.

3. The cyber security system of claim 2 , wherein the nonpredictable environment state includes at least one of a non-predictable memory layout, a non-predictable memory behavior, or a non-predictable property of an object.

4. The cyber security system of claim 2 , wherein the intercepting code is configured to patch an exposed native API of a current execution context and intercept an API invocation of the patched native API, and wherein native API functionality of the patched API is maintained within the nonpredictable environment state.

5. The cyber security system of claim 1 , wherein the modified execution only changes the effect of the intercepted API invocation.

6. The cyber security system of claim 1 , wherein modifying the execution of the intercepted API invocation is performed in response to the determination that the intercepted API invocation is configured to result in a manipulation of a backing store object.

7. A computer-implemented method for cyber security, the method comprising:

receiving, by an application capable of JavaScript execution, code for execution;

executing, before execution of the received code, an intercepting code, wherein the intercepting code is configured to intercept at least one application programming interface (API) invocation by the received code;

intercepting, by the intercepting code, an API invocation by the received code;

determining that the intercepted API invocation is configured to result in a manipulation of a backing store object; and

modifying an execution of the intercepted API invocation, wherein the modified execution changes an effect of the intercepted API invocation, and wherein modifying the execution of the intercepted API invocation includes at least one of:

padding input data associated with the API invocation;

encoding input data associated with the API invocation;

manipulating input data associated with the API invocation;

splitting, into multiple execution contexts, input data associated with the API invocation;

manipulating an object shape associated with the API invocation;

manipulating an object structure associated with the API invocation;

causing an object to reside in an unpredictable memory location;

causing an object to reside in multiple execution contexts; or

causing an object to have random varying properties.

8. The computer-implemented method of claim 7 , wherein the modified execution results in a nonpredictable environment state.

9. The computer-implemented method of claim 8 , wherein the nonpredictable environment state includes at least one of a non-predictable memory layout, a non-predictable memory behavior, or a non-predictable property of an object.

10. The computer-implemented method of claim 8 , wherein the intercepting code is configured to patch an exposed native API of a current execution context and intercept an API invocation of the patched native API, and wherein native API functionality of the patched API is maintained within the nonpredictable environment state.

11. The computer-implemented method of claim 7 , wherein the modified execution only changes the effect of the intercepted API invocation.

12. The computer-implemented method of claim 7 , wherein modifying the execution of the intercepted API invocation is performed in response to the determination that the intercepted API invocation is configured to result in a manipulation of a backing store object.

13. A non-transitory computer-readable medium storing program instructions executable by at least one processor to:

receive, by an application capable of JavaScript execution, code for execution;

execute, before execution of the received code, an intercepting code, wherein the intercepting code is configured to intercept at least one application programming interface (API) invocation by the received code;

intercept, by the intercepting code, an API invocation by the received code;

determine that the intercepted API invocation is configured to result in a manipulation of a backing store object; and

modify an execution of the intercepted API invocation, wherein the modified execution changes an effect of the intercepted API invocation, and wherein modifying the execution of the intercepted API invocation includes at least one of:

padding input data associated with the API invocation;

encoding input data associated with the API invocation;

manipulating input data associated with the API invocation;

splitting, into multiple execution contexts, input data associated with the API invocation;

manipulating an object shape associated with the API invocation;

manipulating an object structure associated with the API invocation;

causing an object to reside in an unpredictable memory location;

causing an object to reside in multiple execution contexts; or

causing an object to have random varying properties.

14. The non-transitory computer-readable medium of claim 13 , wherein the modified execution results in a nonpredictable environment state.

15. The non-transitory computer-readable medium of claim 14 , wherein the nonpredictable environment state includes at least one of a non-predictable memory layout, a non-predictable memory behavior, or a non-predictable property of an object.

16. The non-transitory computer-readable medium of claim 14 , wherein the intercepting code is configured to patch an exposed native API of a current execution context and intercept an API invocation of the patched native API, and wherein native API functionality of the patched API is maintained within the nonpredictable environment state.

17. The non-transitory computer-readable medium of claim 13 , wherein the modified execution only changes the effect of the intercepted API invocation.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jun 25, 2026
From: HSBC BANK PLC
To: SERAPHIC ALGORITHMS LTD
Reel/Frame 075079/0275 →
SECURITY INTEREST Recorded May 12, 2025
From: SERAPHIC ALGORITHMS LTD
To: HSBC BANK PLC
Reel/Frame 071088/0637 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2023
From: COHEN, AVIHAY
To: SERAPHIC ALGORITHMS, LTD.
Reel/Frame 065382/0468 →
Continuity (5)
Continuation 18053138 · Nov 7, 2022
Continuation 17575286 · Jan 13, 2022
Continuation PCTIL2021051062 · Aug 31, 2021
Provisional Application 63072581 · Aug 31, 2020
Related Publication 20240061933A1 · Feb 22, 2024