IP Library Granted Patent US 12,580,902
Granted Patent B2
US 12,580,902 · App. 18/582,705 · Granted Mar 17, 2026

Associating probe to a function in an encrypted connection initiated by the function

Inventors: Santosh Sahu (Karnataka, IN); Puneet Agarwal (Bangalore, IN); Sanjay Nagraj (Dublin, CA)
Assignee: Harness Inc
H04L63/0435H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,902
App. No.
18/582,705
Granted
Mar 17, 2026
Kind
B2
Abstract

A method for associating probe to function in an encrypted connection initiated by the function is disclosed. The method includes receiving data pertaining to an encrypted connection initiated by a function compliant to a secure communication protocol. Next, the method includes identifying a pointer of a structure holding details associated with the initiated encrypted connection. Thereafter, the method includes associating a probe to the function based on the pointer to trace, track, and monitor the function.

Claims (31)

1 . A system comprising:

a receiver module to receive data pertaining to an encrypted connection initiated by a function compliant to a secure communication protocol, wherein the received data is associated with an encrypted data with hidden application layer data with a pointer pointing to an address of a structure holding details associated with the initiated encrypted connection;

a pointer identification module to identify the pointer to the structure holding details associated with the initiated encrypted connection, wherein the structure is allocated during initiation of the encrypted connection, wherein the pointer is created by obtaining the address associated with the structure during initiation of the encrypted connection; and

a probe association module to associate a probe to the function based on the pointer to trace, track, and monitor the function.

2 . The system of claim 1 , wherein the secure communication protocol includes at least one of: Transfer Layer Security (TLS) and Secure Socket Layer (SSL).

3 . The system of claim 1 , wherein the pointer is created during the initialization of the encrypted connection by the function.

4 . The system of claim 1 , wherein the probe corresponds to an extended Berkeley Packet Filter (eBPF) program and includes at least one of: an eBPF uprobe and an eBPF kprobe.

5 . The system of claim 1 , wherein the probe monitors events, associated with the pointer, across lifecycle of the encrypted connection for the tracing, tracking, and monitoring of the function.

6 . The system of claim 1 , further comprises a security breach analysis module to create a behavior fingerprint of the function to determine at least one of: a normal and abnormal traffic behavior in the encrypted connection based on the monitored events.

7 . The system of claim 1 , wherein the probe is associated with the function irrespective of operating system version of a corresponding network asset.

8 . A method comprising:

receiving data pertaining to an encrypted connection initiated by a function compliant to a secure communication protocol, wherein the received data is associated with an encrypted data with hidden application layer data with a pointer pointing to an address of a structure holding details associated with the initiated encrypted connection;

identifying the pointer of to the structure holding details associated with the initiated encrypted connection, wherein the structure is allocated during initiation of the encrypted connection, wherein the pointer is created by obtaining the address associated with the structure during initiation of the encrypted connection; and

associating a probe to the function based on the pointer to trace, track, and monitor the function.

9 . The method of claim 8 , wherein the secure communication protocol includes at least one of: Transfer Layer Security (TLS) and Secure Socket Layer (SSL).

10 . The method of claim 8 , wherein the pointer is created by the function.

11 . The method of claim 8 , wherein the probe corresponds to an extended Berkeley Packet Filter (eBPF) program and includes at least one of: an eBPF uprobe and an eBPF kprobe.

12 . The method of claim 8 , wherein the probe monitors events, associated with the pointer, across lifecycle of the encrypted connection for the tracing, tracking, and monitoring of the function.

13 . The method of claim 8 , further comprises creating a behavior fingerprint of the function to determine at least one of: a normal and abnormal traffic behavior in the encrypted connection based on the monitored events.

14 . The method of claim 8 , wherein the probe is associated with the function irrespective of operating system version of a corresponding network asset.

15 . A computer program product comprising at least one non-transitory computer-readable storage medium having computer-executable program code portions stored therein, the computer program product configured to:

receive data pertaining to an encrypted connection initiated by a function compliant to a secure communication protocol, wherein the received data is associated with an encrypted data with hidden application layer data with a pointer pointing to an address of a structure holding details associated with the initiated encrypted connection;

identify the pointer to the structure holding details associated with the initiated encrypted connection, wherein the structure is allocated during initiation of the encrypted connection, wherein the pointer is created by obtaining the address associated with the structure during initiation of the encrypted connection; and

associate a probe to the function based on the pointer to trace, track, and monitor the function.

16 . The computer program product of claim 15 , wherein the secure communication protocol includes at least one of: Transfer Layer Security (TLS) and Secure Socket Layer (SSL).

17 . The computer program product of claim 15 , wherein the pointer is created by the function.

18 . The computer program product of claim 15 ,

wherein the probe corresponds to an extended Berkeley Packet Filter (eBPF) program and includes at least one of: an eBPF uprobe and an eBPF kprobe; and

wherein the probe monitors events, associated with the pointer, across lifecycle of the encrypted connection for the tracing, tracking, and monitoring of the function.

19 . The computer program product of claim 15 , further comprises creating a behavior fingerprint of the function to determine at least one of: a normal and abnormal traffic behavior in the encrypted connection based on the monitored events.

20 . The computer program product of claim 15 , wherein the probe is associated with the function irrespective of operating system version of a corresponding network asset.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0062 →
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0281 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 074240/0665 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
Reel/Frame 074240/0707 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2025
From: TRACEABLE INC.
To: HARNESS INC.
Reel/Frame 071911/0025 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2024
From: SAHU, SANTOSH, MR.; AGARWAL, PUNEET, MR.; NAGRAJ, SANJAY, MR.
To: TRACEABLE INC
Reel/Frame 066710/0955 →
Continuity (1)
Related Publication 20250267131A1 · Aug 21, 2025
References Cited (4)
US 20190028496A1 · Fenoglio · 2019 [cited by examiner]
US 20220147542A1 · Asgar · 2022 [cited by examiner]
US 20230090689A1 · Knierim · 2023 [cited by examiner]
US 20240275816A1 · Guo · 2024 [cited by examiner]