IP Library Granted Patent US 12,437,082
Granted Patent B2
US 12,437,082 · App. 18/790,022 · Granted Oct 7, 2025

System and method for automated exploitation generation

Inventors: Leander A. Metcalf, II (Millersville, MD); Allen Stewart (Atlanta, GA)
Assignee: BOOZ ALLEN HAMILTON INC.
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,082
App. No.
18/790,022
Granted
Oct 7, 2025
Kind
B2
Abstract

Embodiments can relate to a system for automated exploit generation that receives input data representative of a target action to establish a target having a potential target vulnerability. The system can build a simulated target environment that includes the established target. The system can conduct an analysis method including a static, a concrete, a dynamic, and/or a symbolic analysis. The system can create a chainable sequence including an information disclosure, a read, a write, and/or an execution exploit primitive. The system can generate an exploit chain that, when executed by the processor in response to the target action, can transform the target action to a target failure within the simulated target environment and thereby expose the target vulnerability. The system can execute the exploit chain within the simulated target environment to examine coverage of the exposed target vulnerability. The system can generate an output representative of the exposed target vulnerability.

Claims (52)

1. A system for automated exploit generation, the system comprising:

a processor; and

a memory associated with the processor having instructions stored thereon that when executed will cause the processor to:

receive input data representative of a target action to establish a target having a potential target vulnerability;

build a simulated or emulated target environment that includes the established target;

conduct an analysis method including one or more of a static, a concrete, a dynamic, or a symbolic analysis of one or more exploitation techniques, the analysis method configured to generate one or more artifacts including one or more behavioral signatures of exploit primitives that translate across different and disparate exploitation techniques;

create a chainable sequence including the one or more artifacts and one or more of an information disclosure, a read, a write, or an execution exploit primitive;

generate an exploit chain that, when executed by the processor in response to the target action, will transform the target action to a target failure within the simulated or emulated target environment and thereby expose the target vulnerability, the exploit chain including the chainable sequence;

execute the exploit chain within the simulated or emulated target environment to examine coverage of the exposed target vulnerability; and

generate an output representative of the exposed target vulnerability.

2. The system of claim 1 , wherein:

the target is of one or more of a software target, a device target, or an operating system target.

3. The system of claim 1 , wherein:

the exploit chain includes a series of events that transforms the target action to the target failure.

4. The system of claim 1 , wherein:

the exploit chain includes one or more of a path constraint, an execution trace, a performance metric, or metadata.

5. The system of claim 4 , wherein:

metadata includes pre-target failure metadata and post-target failure metadata.

6. The system of claim 1 , wherein:

the exploit chain is generated from an exploit primitive.

7. The system of claim 1 , wherein:

the target vulnerability includes one or more of an error vulnerability, a flaw vulnerability, or an undesired behavior vulnerability.

8. The system of claim 1 , wherein:

exposing the target vulnerability includes exposing a proof of the target vulnerability.

9. The system of claim 1 , wherein:

the output representative of the exposed target vulnerability is generated in one or more diversified forms.

10. The system of claim 9 , wherein:

the one or more diversified forms includes exported exploit demonstration script or system executable shellcode.

11. A computer readable medium having instructions thereon that when executed by a processor will cause the processor to:

receive input data representative of a target action to establish a target having a potential target vulnerability;

build a simulated or emulated target environment that includes the established target;

conduct an analysis method including one or more of a static, a concrete, a dynamic, or a symbolic analysis of one or more exploitation techniques, the analysis method configured to generate one or more artifacts including one or more behavioral signatures of exploit primitives that translate across different and disparate exploitation techniques;

create a chainable sequence including the one or more artifacts and one or more of an information disclosure, a read, a write, or an execution exploit primitive;

generate an exploit chain that, when executed by a processor in response to the target action, will transform the target action to a target failure within the simulated or emulated target environment and thereby expose the target vulnerability;

execute the exploit chain within the simulated or emulated target environment to examine coverage of the exposed target vulnerability; and

generate an output representative of the exposed target vulnerability.

12. The computer readable medium of claim 11 , wherein:

the target is of one or more of a software target, a device target, or an operating system target.

13. The computer readable medium of claim 11 , wherein:

the exploit chain includes a series of events that transforms the target action to the target failure.

14. A method for automated exploit generation, the method comprising:

receiving input data representative of a target action to establish a target having a potential target vulnerability;

building a simulated target environment that includes the established target;

conducting an analysis method including one or more of a static, a concrete, a dynamic, or a symbolic analysis of one or more exploitation techniques, the analysis method configured to generate one or more artifacts including one or more behavioral signatures of exploit primitives that translate across different and disparate exploitation techniques;

create a chainable sequence including the one or more artifacts and one or more of an information disclosure, a read, a write, or an execution exploit primitive;

generating an exploit chain that, when executed by a processor in response to the target action, will transform the target action to a target failure within the simulated or emulated target environment and thereby expose the target vulnerability, the exploit chain including the chainable sequence;

executing the exploit chain within the simulated or emulated target environment to examine coverage of the exposed target vulnerability; and

generating an output representative of the exposed target vulnerability.

15. The method of claim 14 , wherein:

the target is of one or more of a software target, a device target, or an operating system target.

16. The method of claim 14 , wherein:

the exploit chain includes a series of events that transforms the target action to the target failure.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2024
From: METCALF, LEANDER A., II; STEWART, ALLEN
To: BOOZ ALLEN HAMILTON INC.
Reel/Frame 068538/0457 →
Continuity (2)
Provisional Application 63516661 · Jul 31, 2023
Related Publication 20250045418A1 · Feb 6, 2025
References Cited (10)
US 8296848B1 · Griffin · 2012 [cited by examiner]
US 20060277539A1 · Amarasinghe · 2006 [cited by examiner]
US 20080098479A1 · O'Rourke · 2008 [cited by examiner]
US 20100138925A1 · Barai · 2010 [cited by examiner]
US 20150326592A1 · Vissamsetty · 2015 [cited by examiner]
US 20190238583A1 · Vaidya · 2019 [cited by examiner]
US 20220232033A1 · Vaidya · 2022 [cited by examiner]
US 20220377102A1 · Sharma · 2022 [cited by examiner]
US 20230222223A1 · Lahmadi · 2023 [cited by examiner]
International Search Report and Written Opinion of the International Searching Authority (Forms PCT/ISA/220, PCT/ISA/210 and PCT/ISA/237) issued on Jun. 16, 2025, by the International Bureau of the U.S. Patent and Trade… [cited by applicant]