IP Library › Granted Patent US 12,579,276
Granted Patent B2
US 12,579,276 · App. 17/835,074 · Granted Mar 17, 2026

Application vulnerability score based on stack traces

Inventors: Ashutosh Kulshreshtha (Cupertino, CA); Walter T. Hulick, Jr. (Pearland, TX); Chandra Mohan Babu Nadiminti (Dublin, CA)
Assignee: Cisco Technology, Inc.
G06F21/577G06F21/52G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,276
App. No.
17/835,074
Granted
Mar 17, 2026
Kind
B2
Abstract

A computing system for identifying and scoring problems associated with call stacks. The computing system identifies call stacks associated with an application and determines a problem occurs in the application. The computer system compares a call stack of a first set of applications with a call stack of a second set of applications, wherein the call stack of the first set of applications includes the problem and the call stack of the second set of applications does not include the problem. The computer system generates a score indicating a likelihood that a particular call stack caused the problem based on whether the particular call stack is included in the call stack of the first set of applications, the call stack of the second set of applications, or both. The computing system generates a notification comprising the score indicating the likelihood that the particular call stack caused the problem.

Claims (55)

1 . A computing system, the computing system comprising:

one or more processors; and

one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the computing system to perform operations comprising:

training a machine learning model with a first set of call stacks associated with a first application, wherein the first application causes a problem;

training the machine learning model with a second set of call stacks associated with a second application, wherein the second application does not cause the problem;

using the trained machine learning model to generate a problem likelihood score for a first call stack of the first set of call stacks, wherein the problem likelihood score indicates a predicted probability that the first call stack caused the problem;

determining one or more call stacks associated with a new application;

determining whether the problem occurs in the new application;

comparing, in response to determining that the problem occurs, the one or more call stacks associated with the new application to the first call stack; and

generating a score indicating a likelihood that the first call stack caused the problem in the new application.

2 . The computing system of claim 1 , wherein the instructions cause the one or more components of the computing system to perform further operations comprising generating a notification comprising the score indicating the likelihood that the first call stack caused the problem.

3 . The computing system of claim 2 , wherein:

the new application is instantiated in a development environment; and

the notification is sent prior to execution of the new application.

4 . The computing system of claim 1 , wherein the instructions cause the one or more components of the computing system to perform further operations comprising receiving traces of the one or more call stacks of the new application to determine whether the problem occurs in the new application.

5 . The computing system of claim 1 , wherein the problem includes one of a known vulnerability, a known weakness, and both a known vulnerability and a known weakness.

6 . The computing system of claim 1 , wherein the instructions cause the one or more components of the computing system to perform further operations comprising:

storing known application vulnerabilities and associated applications, call stacks, system calls, application versions, call stack versions, and call iterations in a knowledge database; and

further training the machine learning model using, at least in part, a test data set, the test data set derived from the known application vulnerabilities and the call stacks associated with the known application vulnerabilities.

7 . The computing system of claim 1 , wherein generating the score indicating the likelihood that the first call stack caused the problem in the new application is based on whether the first call stack is included in the new application.

8 . A method performed by a computing system, the method comprising:

training a machine learning model with a first set of call stacks associated with a first application, wherein the first application causes a problem;

training the machine learning model with a second set of call stacks associated with a second application, wherein the second application does not cause the problem;

using the trained machine learning model to generate a problem likelihood score for a first call stack of the first set of call stacks, wherein the problem likelihood score indicates a predicted probability that the first call stack caused the problem;

determining one or more call stacks associated with a new application;

determining whether the problem occurs in the new application;

comparing, in response to determining that the problem occurs, the one or more call stacks associated with the new application to the first call stack; and

generating a score indicating a likelihood that the first call stack caused the problem in the new application.

9 . The method of claim 8 , further comprising generating a notification comprising the score indicating the likelihood that the first call stack caused the problem.

10 . The method of claim 9 , wherein:

The new application is instantiated in a development environment; and

the notification is sent prior to execution of the new application.

11 . The method of claim 8 , further comprising receiving traces of the one or more call stacks of the new application to determine whether the problem occurs in the new application.

12 . The method of claim 8 , wherein the problem includes one of a known vulnerability, a known weakness, and both a known vulnerability and a known weakness.

13 . The method of claim 8 , further comprising:

storing known application vulnerabilities and associated applications, call stacks, system calls, application versions, call stack versions, and call iterations in a knowledge database; and

further training the machine learning model using, at least in part, a test data set, the test data set derived from the known application vulnerabilities and the call stacks associated with the known application vulnerabilities.

14 . The method of claim 8 , wherein generating the score indicating the likelihood that the first call stack caused the problem in the new application is based on whether the first call stack is included in the new application.

15 . One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor of a computing system, cause performance of operations comprising:

training a machine learning model with a first set of call stacks associated with a first application, wherein the first application causes a problem;

training the machine learning model with a second set of call stacks associated with a second application, wherein the second application does not cause the problem;

using the trained machine learning model to generate a problem likelihood score for a first call stack of the first set of call stacks, wherein the problem likelihood score indicates a predicted probability that the first call stack caused the problem;

determining one or more call stacks associated with a new application;

determining whether the problem occurs in the new application;

comparing, in response to determining that the problem occurs, the one or more call stacks associated with the new application to the first call stack; and

generating a score indicating a likelihood that the first call stack caused the problem in the new application.

16 . The one or more computer-readable non-transitory storage media of claim 15 , wherein the instructions cause the performance of further operations comprising generating a notification comprising the score indicating the likelihood that the first call stack caused the problem.

17 . The one or more computer-readable non-transitory storage media of claim 16 , wherein:

the new application is instantiated in a development environment; and

the notification is sent prior to execution of the new application.

18 . The one or more computer-readable non-transitory storage media of claim 15 , wherein the problem includes one of a known vulnerability, a known weakness, and both a known vulnerability and a known weakness.

19 . The one or more computer-readable non-transitory storage media of claim 15 , wherein generating the score indicating the likelihood that the first call stack caused the problem in the new application is based on whether the first call stack is included in the new application.

20 . The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising:

storing known application vulnerabilities and associated applications, call stacks, system calls, application versions, call stack versions, and call iterations in a knowledge database; and

further training the machine learning model using, at least in part, a test data set, the test data set derived from the known application vulnerabilities and the call stacks associated with the known application vulnerabilities.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2022
From: KULSHRESHTHA, ASHUTOSH; HULICK, WALTER T., JR.; NADIMINTI, CHANDRA MOHAN BABU
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060133/0283 →
Continuity (2)
Provisional Application 63308681 · Feb 10, 2022
Related Publication 20230252162A1 · Aug 10, 2023
References Cited (28)
US 10019572B1 · Sharifi Mehr · 2018 [cited by examiner]
US 10868825B1 · Dominessy · 2020 [cited by examiner]
US 11042647B1 · Joyce et al. · 2021 [cited by applicant]
US 20100095157A1 · Aoyama · 2010 [cited by examiner]
US 20100153785A1 · Keromytis · 2010 [cited by examiner]
US 20130080502A1 · Mccoll · 2013 [cited by examiner]
US 20150237063A1 · Cotton et al. · 2015 [cited by applicant]
US 20160300060A1 · Pike · 2016 [cited by examiner]
US 20170046518A1 · Chen · 2017 [cited by examiner]
US 20170124319A1 · Peleg · 2017 [cited by examiner]
US 20170161498A1 · Yavo · 2017 [cited by examiner]
US 20190121985A1 · Hoole · 2019 [cited by examiner]
US 20190196937A1 · Wang · 2019 [cited by examiner]
US 20200167271A1 · Zhang · 2020 [cited by examiner]
US 20200210580A1 · Strogov · 2020 [cited by examiner]
US 20200311268A1 · Kostyushko · 2020 [cited by examiner]
US 20200342113A1 · Yi et al. · 2020 [cited by applicant]
US 20200349259A1 · Tsai · 2020 [cited by examiner]
US 20210011717A1 · Lin · 2021 [cited by examiner]
US 20210049265A1 · Pescatore · 2021 [cited by examiner]
US 20210157924A1 · Antoniadis · 2021 [cited by examiner]
US 20210173760A1 · Downie · 2021 [cited by examiner]
US 20210216643A1 · Mishra et al. · 2021 [cited by applicant]
US 20210263924A1 · Klein · 2021 [cited by examiner]
US 20210326446A1 · Cao · 2021 [cited by examiner]
US 20230281322A1 · Powers · 2023 [cited by examiner]
CN 113076541A · 2021 [cited by applicant]
Jidiga, Goverdhan Reddy; Sammulal, P.; “Anomaly detection using smart tracing tricks on call stack,” International Conference for Convergence for Technology, Pune, India, Apr. 6-8, 2014, IEEE, pp. 1-6. [cited by examiner]