IP Library Granted Patent US 12,499,231
Granted Patent B2
US 12,499,231 · App. 18/084,065 · Granted Dec 16, 2025

Inline control flow monitor with enforcement

Inventors: Andrew Zawadowskiy (Hollis, NH); Oleg Bessonov (Littleton, MA); Vincent E. Parla (North Hampton, NH)
Assignee: Cisco Technology, Inc.
G06F21/566G06F8/433G06F8/75G06F9/44589G06F11/3616G06F21/51G06F21/53G06F21/54G06F21/552G06F21/577H04L63/1416H04L63/1425H04L63/1433G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,231
App. No.
18/084,065
Granted
Dec 16, 2025
Kind
B2
Abstract

Techniques and systems described herein relate to monitoring executions of computer instructions on computing devices based on learning and generating a control flow directed graph. The techniques and systems include determining a learned control flow directed graph for a process executed on the computing system. A system call is identified during execution of the process as well as a predetermined number of transitions leading to the system call. A validity of the transitions leading the system call is determined based on the learned control flow directed graph and the computing system may perform an action based on the validity.

Claims (41)

1 . A method for monitoring a computing system, comprising:

determining a learned control flow directed graph for a process executed on a computing system, the learned control flow directed graph representing a valid sequence of transitions or a valid number of transitions for a process executed on the computing system that were observed in a monitoring phase;

determining an intercepted system call during execution of the process;

determining a predetermined sequence of transitions or predetermined number of transitions leading to the intercepted system call;

determining a validity for execution of the processes based at least in part on a comparison of the valid sequence of transitions or a valid number of transitions and the predetermined sequence of transitions or predetermined number of transitions; and

causing the computing system to perform an action based at least in part on the validity.

2 . The method of claim 1 , wherein determining the system call comprises:

capturing, via a central processing unit (CPU) of the computing system, telemetry associated with the process; and

maintaining, in memory of the computing system, a predetermined number of batches of the telemetry.

3 . The method of claim 2 , wherein determining the predetermined number of transitions comprises determining transitions included in the predetermined number of batches of the telemetry.

4 . The method of claim 2 , wherein determining the validity of the predetermined number of transitions comprises decoding the telemetry to determine transitions and comparing the transitions against the learned control flow directed graph.

5 . The method of claim 1 , wherein the action comprises determining an error in response to determining that at least one of the predetermined number of transitions is invalid based on the at least one of the predetermined number of transitions not being included in the learned control flow directed graph.

6 . The method of claim 1 , wherein the action comprises performing the intercepted system call in response to determining that the predetermined number of transitions are included in the learned control flow directed graph.

7 . The method of claim 1 , wherein determining the learned control flow directed graph comprises observing execution of the process until at least a threshold percentage of code associated with the process is observed.

8 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

determining a learned control flow directed graph for a process executed on a computing system, the learned control flow directed graph representing a valid sequence of transitions or a valid number of transitions for a process executed on the computing system that were observed in a monitoring phase;

determining an intercepted system call during execution of the process;

determining a predetermined sequence of transitions or predetermined number of transitions leading to the intercepted system call;

determining a validity for execution of the processes based at least in part on a comparison of the valid sequence of transitions or a valid number of transitions and the predetermined sequence of transitions or predetermined number of transitions; and

causing the computing system to perform an action based at least in part on the validity.

9 . The system of claim 8 , wherein determining the predetermined number of transitions leading to the intercepted system call comprises determining a risk score associated with the intercepted system call, and wherein the predetermined number of transitions is based at least in part on the risk score.

10 . The system of claim 8 , the operations further comprising storing a predetermined number of recent batches of telemetry in a memory of the system, and wherein determining the predetermined number of transitions is based at least in part on processing the telemetry to identify transitions from the telemetry.

11 . The system of claim 10 , wherein determining the validity of the predetermined number of transitions comprises decoding the telemetry to determine transitions and comparing the transitions against the learned control flow directed graph.

12 . The system of claim 8 , wherein determining the validity for the predetermined number of transitions comprises identifying the predetermined number of transitions within the learned control flow directed graph.

13 . The system of claim 12 , wherein in response to one or more of the predetermined number of transitions not being within the learned control flow directed graph, the action comprises generating an error and preventing execution of the system call.

14 . The system of claim 8 , wherein determining the learned control flow directed graph comprises observing execution of the process until at least a threshold percentage of code associated with the process is observed.

15 . One or more non-transitory computer-readable media storing computer-readable instructions that, when executed by one or more processors, cause the one or more processors to:

determine a learned control flow directed graph for a process executed on a computing system, the learned control flow directed graph representing a valid sequence of transitions or a valid number of transitions for a process executed on the computing system that were observed in a monitoring phase;

determine an intercepted system call during execution of the process;

determine a predetermined sequence of transitions or predetermined number of transitions leading to the intercepted system call;

determine a validity for execution of the processes based at least in part on a comparison of the valid sequence of transitions or a valid number of transitions and the predetermined sequence of transitions or predetermined number of transitions; and

cause the computing system to perform an action based at least in part on the validity.

16 . The one or more non-transitory computer-readable media of claim 15 , the instructions comprising further instructions that, when executed by the one or more processors, cause the one or more processors to additionally: store a predetermined number of recent batches of telemetry in a memory of the system, and wherein the instructions to determine the predetermined number of transitions is based at least in part on processing the telemetry to identify transitions from the telemetry.

17 . The one or more non-transitory computer-readable media of claim 15 , wherein the instructions to determine the validity for the predetermined number of transitions comprises identifying the predetermined number of transitions within the learned control flow directed graph.

18 . The one or more non-transitory computer-readable media of claim 17 , wherein in response to one or more of the predetermined number of transitions not being within the learned control flow directed graph, the action comprises generating an error and preventing execution of the intercepted system call.

19 . The one or more non-transitory computer-readable media of claim 15 , wherein the instructions to determine the predetermined number of transitions leading to the intercepted system call comprises determining a risk score associated with the intercepted system call, and wherein the predetermined number of transitions is based at least in part on the risk score.

20 . The one or more non-transitory computer-readable media of claim 15 , wherein the instructions to determine the system call comprises:

capturing, via a central processing unit (CPU) of the computing system, telemetry associated with the process; and

maintaining, in memory of the computing system, a predetermined number of batches of the telemetry.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2022
From: ZAWADOWSKIY, ANDREW; BESSONOV, OLEG; PARLA, VINCENT E
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062146/0148 →
Continuity (3)
Provisional Application 63391560 · Jul 22, 2022
Provisional Application 63391518 · Jul 22, 2022
Related Publication 20240028709A1 · Jan 25, 2024
References Cited (151)
US 5933640A · Dion · 1999 [cited by applicant]
US 7984304B1 · Waldspurger · 2011 [cited by applicant]
US 8230505B1 · Ahrens et al. · 2012 [cited by applicant]
US 8407322B1 · Sasikumar et al. · 2013 [cited by applicant]
US 8682985B2 · Pulla et al. · 2014 [cited by applicant]
US 9021589B2 · Anderson et al. · 2015 [cited by applicant]
US 9158915B1 · Yumer · 2015 [cited by applicant]
US 9454659B1 · Daymont · 2016 [cited by applicant]
US 9696989B1 · Korotaev · 2017 [cited by applicant]
US 9953158B1 · Benameur et al. · 2018 [cited by applicant]
US 10084815B2 · Falkowitz et al. · 2018 [cited by applicant]
US 10203968B1 · Lawson · 2019 [cited by applicant]
US 10310863B1 · Poimboeuf · 2019 [cited by applicant]
US 10691575B2 · Lengauer · 2020 [cited by examiner]
US 10706144B1 · Moritz · 2020 [cited by applicant]
US 10915636B1 · Kaplan · 2021 [cited by applicant]
US 11003746B1 · Vashishtha et al. · 2021 [cited by applicant]
US 11018959B1 · Neill · 2021 [cited by applicant]
US 11138314B1 · Gettys et al. · 2021 [cited by applicant]
US 11349670B1 · Miller · 2022 [cited by applicant]
US 11556444B1 · Rohithakshappa · 2023 [cited by examiner]
US 11556452B2 · Danielson et al. · 2023 [cited by applicant]
US 11809535B2 · Magi et al. · 2023 [cited by applicant]
US 11847044B2 · Krishnan et al. · 2023 [cited by applicant]
US 11947663B2 · Sethumadhavan et al. · 2024 [cited by applicant]
US 11971807B2 · Kroehling · 2024 [cited by applicant]
US 12326936B2 · Zawadowskiy et al. · 2025 [cited by applicant]
US 20030078782A1 · Blair · 2003 [cited by examiner]
US 20050010804A1 · Bruening et al. · 2005 [cited by applicant]
US 20060161978A1 · Abadi et al. · 2006 [cited by applicant]
US 20060174077A1 · Abadi et al. · 2006 [cited by applicant]
US 20070160191A1 · Blair · 2007 [cited by examiner]
US 20090055571A1 · Budko et al. · 2009 [cited by applicant]
US 20090328211A1 · Abraham et al. · 2009 [cited by applicant]
US 20100180258A1 · Takahashi · 2010 [cited by applicant]
US 20100275186A1 · McGarvey et al. · 2010 [cited by applicant]
US 20120066166A1 · Curbera · 2012 [cited by examiner]
US 20120222019A1 · Gounares et al. · 2012 [cited by applicant]
US 20130031531A1 · Keynes · 2013 [cited by applicant]
US 20130055210A1 · Murthy et al. · 2013 [cited by applicant]
US 20130151831A1 · Bealkowski et al. · 2013 [cited by applicant]
US 20130291113A1 · Dewey · 2013 [cited by applicant]
US 20130326625A1 · Anderson · 2013 [cited by examiner]
US 20140337086A1 · Asenjo · 2014 [cited by applicant]
US 20150161383A1 · Chen et al. · 2015 [cited by applicant]
US 20150356294A1 · Tan · 2015 [cited by applicant]
US 20160283712A1 · Kanhere et al. · 2016 [cited by applicant]
US 20160300063A1 · Daymont · 2016 [cited by applicant]
US 20170017789A1 · Daymont · 2017 [cited by applicant]
US 20170024562A1 · Rombouts et al. · 2017 [cited by applicant]
US 20170090929A1 · Muttik · 2017 [cited by examiner]
US 20170116108A1 · Miskelly · 2017 [cited by applicant]
US 20170169229A1 · Brucker et al. · 2017 [cited by applicant]
US 20170185775A1 · Boehm · 2017 [cited by examiner]
US 20170255416A1 · Zhang · 2017 [cited by examiner]
US 20170359220A1 · Weith · 2017 [cited by applicant]
US 20180060209A1 · Kim · 2018 [cited by applicant]
US 20180095764A1 · Sultana · 2018 [cited by applicant]
US 20180096147A1 · Ince · 2018 [cited by examiner]
US 20180101565A1 · Pike · 2018 [cited by applicant]
US 20180121654A1 · Bobritsky · 2018 [cited by applicant]
US 20180211046A1 · Muttik et al. · 2018 [cited by applicant]
US 20180225446A1 · Liu · 2018 [cited by examiner]
US 20180316698A1 · David et al. · 2018 [cited by applicant]
US 20180349603A1 · Yamada · 2018 [cited by examiner]
US 20190042730A1 · Yamada · 2019 [cited by examiner]
US 20190050566A1 · LeMay et al. · 2019 [cited by applicant]
US 20190065743A1 · Shibahara et al. · 2019 [cited by applicant]
US 20190108342A1 · Conikee et al. · 2019 [cited by applicant]
US 20190121979A1 · Chari et al. · 2019 [cited by applicant]
US 20190129825A1 · Bardin et al. · 2019 [cited by applicant]
US 20190171423A1 · Mishra · 2019 [cited by applicant]
US 20190207969A1 · Brown · 2019 [cited by applicant]
US 20190294790A1 · Chang · 2019 [cited by applicant]
US 20190347415A1 · Yavo · 2019 [cited by applicant]
US 20200004954A1 · Zawadowskiy · 2020 [cited by examiner]
US 20200012786A1 · Lamothe-Brassard · 2020 [cited by applicant]
US 20200057856A1 · Daymont · 2020 [cited by applicant]
US 20200143061A1 · Kim · 2020 [cited by applicant]
US 20200162483A1 · Farhady et al. · 2020 [cited by applicant]
US 20200242239A1 · Loman et al. · 2020 [cited by applicant]
US 20200314124A1 · Reybok, Jr. et al. · 2020 [cited by applicant]
US 20200382560A1 · Woolward · 2020 [cited by applicant]
US 20200394313A1 · Ionescu · 2020 [cited by applicant]
US 20210089400A1 · Kashani · 2021 [cited by examiner]
US 20210097168A1 · Patel et al. · 2021 [cited by applicant]
US 20210133324A1 · Chari et al. · 2021 [cited by applicant]
US 20210152588A1 · Cruz · 2021 [cited by applicant]
US 20210157583A1 · Yuile · 2021 [cited by examiner]
US 20210182393A1 · Chevalier et al. · 2021 [cited by applicant]
US 20210216634A1 · Kenyon · 2021 [cited by applicant]
US 20210232680A1 · Hecht · 2021 [cited by applicant]
US 20210264031A1 · Dhillon et al. · 2021 [cited by applicant]
US 20210279338A1 · Bowman et al. · 2021 [cited by applicant]
US 20210286600A1 · Calvano et al. · 2021 [cited by applicant]
US 20210312082A1 · Conikee · 2021 [cited by applicant]
US 20210390182A1 · Boutnaru · 2021 [cited by applicant]
US 20220019657A1 · Sethumadhavan · 2022 [cited by examiner]
US 20220092179A1 · Zhang et al. · 2022 [cited by applicant]
US 20220108007A1 · Zatutschne-Marom et al. · 2022 [cited by applicant]
US 20220391532A1 · Le et al. · 2022 [cited by applicant]
US 20230012722A1 · Del Rosario · 2023 [cited by applicant]
US 20230017384A1 · Woodward et al. · 2023 [cited by applicant]
US 20230020547A1 · Katkoori et al. · 2023 [cited by applicant]
US 20230195860A1 · Porter · 2023 [cited by examiner]
US 20230289451A1 · Mackenbach · 2023 [cited by applicant]
US 20230315439A1 · Castrejon, III et al. · 2023 [cited by applicant]
US 20230367882A1 · Bussell et al. · 2023 [cited by applicant]
US 20230379342A1 · Gilad et al. · 2023 [cited by applicant]
US 20240028701A1 · Zawadowskiy · 2024 [cited by applicant]
US 20240028708A1 · Zawadowskiy · 2024 [cited by applicant]
US 20240028712A1 · Parla · 2024 [cited by applicant]
US 20240028724A1 · Parla · 2024 [cited by applicant]
US 20240028741A1 · Parla · 2024 [cited by applicant]
US 20240028742A1 · Zawadowskiy · 2024 [cited by applicant]
US 20240028743A1 · Parla · 2024 [cited by applicant]
US 20240031394A1 · Parla · 2024 [cited by applicant]
US 20240089272A1 · Gilad et al. · 2024 [cited by applicant]
CN 110268411A · 2019 [cited by applicant]
CN 111062038 · 2020 [cited by applicant]
CN 112818356A · 2021 [cited by applicant]
CN 113569244 · 2021 [cited by applicant]
CN 113434870B · 2022 [cited by applicant]
KR 102392642B1 · 2022 [cited by examiner]
Da Silva, A. C. F., et al. (2022). Using a cyber digital twin for continuous automotive security requirements verification. IEEE Software. 10 pages. [cited by applicant]
Hiremagalore, Sharath “Zero-Day Web Attack Detection Using Collaborative and Transduction-Based Anomaly Detectors” George Mason University; published Nov. 9, 2021, 99 pages. [cited by applicant]
Maunero, et al. “A FPGA-Based Control-Flow Integrity Solution for Securing Bare-Metal Embedded Systems” Institute of Electrical and Electronics Engineers Inc. 2020, 11 pages. [cited by applicant]
Altinay, et al; “BinRec: Dynamic Binary Lifting and Recompilation”, Proceedings of the 12th IEEE/ACM International Conference on Utility and Cloud Computing, Apr. 15, 2020, pp. 1-16. [cited by applicant]
Bardin, et al; “Backward-Bounded DSE: Targeting Infeasibility Questions on Obfuscated Codes”, 2017 IEEE Symposium on Security and Privacy (SP), IEEE, May 22, 2017, pp. 633-651. [cited by applicant]
Delozier et al., “Hurdle, Securing Jump Instructions Against Code Reuse Atttacks”, Proceeduings of the 25th International Conference on Architechtural Support for Programming Languages and Operating Systems, ACM, New Yo… [cited by applicant]
Kumar, S., Moolchandani, D., & Sarangi, S. R. (2022). Hardware-assisted mechanisms to enforce control flow integrity: A comprehensive survey. Journal of Systems Architecture, 102644. [cited by applicant]
Liu, et al; “Transparent and Efficient CFI Enforcement with Intel Processor Trace,” 2017 IEEE International Symposium on High Performance Computer Architecture (HPCA), IEEE, US, Feb. 4, 2017, pp. 529-540. [cited by applicant]
PCT Search Report and Written Opinion mailed Apr. 15, 2024 for PCT application No. PCT/US2023/028282, 15 pages. [cited by applicant]
PCT Search Report and Written Opinion mailed Apr. 15, 2024 for PCT application No. PCT/US2023/084664, 14 pages. [cited by applicant]
PCT Search Report and Written Opinion mailed Apr. 24, 2024 for PCT application No. PCT/US2023/084670, 14 pages. [cited by applicant]
PCT Search Report and Written Opinion mailed Apr. 29, 2024 for PCT application No. PCT/US2023/084901, 13 pages. [cited by applicant]
PCT Search Report and Written Opinion mailed May 3, 2024 for PCT application No. PCT /US2023/084659, 14 pages. [cited by applicant]
PCT Search Report and Written Opinion Dated Apr. 25, 2024 for PCT Application No. PCT/US2023/084668, 15 pges. [cited by applicant]
Qiang, “CloudFI: Context-Sensitive and Incremental CFI in the Cloud Environment”, IEEE Transactions on Cloud Computing, IEEE Computer Society, USA vo1. 9, No. 3, Mar. 1, 2019 pp. 938-957. [cited by applicant]
Xinyang, et al; Griffin: Guarding Control Flows Using Intel Processor Trace, Architectural support for programming languages and Operating systems, Apr. 4, 2017, pp. 585-598. [cited by applicant]
Yuan, et al., “Hardware-Assisted 1-23 Fine-Grained Code-Reuse Attack Detection”, Dec. 12, 2015, SAT 2015 18th International Conference , Austin, TX, USA, Sep. 24-27, 2015 ; [Lecture Notes in Computer Science; Lect . Not… [cited by applicant]
Zhang et al: “DeepCheck: A Non-intrusive Control-flow Integrity Checking based on Deep Learning”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY1, May 6, 2019, 10 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/083,838, Dated Oct. 31, 2024, Zawadowsky, “Control Flow Directed Graph for Use With Program Disassembler,” 9 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/084,093, Dated Feb. 27, 2025, Parla,“Control Flow Prevention Using Software Bill of Materials Analysis,” 33 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/084,147, Dated Mar. 20, 2025, Parla,“Control Flow Integrity Enforcement for Applications Running on Platforms,” 24 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/084,177, dated Jan. 13, 2025, 31 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/084,007, dated Jan. 29, 2025, 26 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/084,007, Dated Oct. 22, 2024, Parla, “Control Flow Integrity Monitoring Based Insights”, 37 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/084,121, dated Sep. 11, 2024, 24 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/084,147, dated Sep. 6, 2024, 17 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/084,093, dated Aug. 29, 2024, 16 pages. [cited by applicant]