IP Library › Granted Patent US 12,585,478
Granted Patent B1
US 12,585,478 · App. 18/671,889 · Granted Mar 24, 2026

Dynamically-updatable deep transactional monitoring systems and methods

Inventor: Beth Hunt (Denver, CO)
Assignee: TECH HEIGHTS LLC
G06F9/44521G06F11/302G06F11/3495
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,478
App. No.
18/671,889
Filed
May 22, 2024
Granted
Mar 24, 2026
Kind
B1
Art Unit
2194
USPC
719/320
Abstract

Provided herein are system, method and computer program products for providing dynamically-updatable deep transactional monitoring of running applications in real-time. A method for monitoring a target software application operates by injecting a software engine into a new thread within a target process of the target software application. The method then retrieves a monitoring script and initiates execution of the monitoring script within the software engine. The monitoring script determining the address functions and calls to the functions and inserts a trampoline call within the one or more functions. The trampoline saves the execution state of the target process and calls a corresponding monitoring function that to retrieves data associated with the target process. The method then restoring the execution state of the target process and resumes execution of the target function.

Claims (24)

1 . A computer-implemented method of modifying a target application executing in a target process including one or more target threads, the computer-implemented method comprising:

creating a monitoring thread in the target process different than the one or more target threads during runtime of the target process;

starting execution of a software engine in the monitoring thread in the target process, during the runtime of the target process, to execute one or more monitoring scripts during the runtime of the target process, wherein the one or more monitoring scripts executing in the monitoring thread are configured to access memory within the target process and the target application executing in the one or more target threads are configured to access the memory within the target process;

modifying, by execution of the one or more monitoring scripts, executable code of the target application during the runtime of the target process, wherein the modified executable code is configured to generate monitoring data from the runtime of the target process and to store the monitoring data into the memory during the runtime of the target process, wherein the modifying operation includes modifying one or more instructions in a target function of the target application during runtime of the target process to include instructions that call monitoring interceptor code within the one or more monitoring scripts; and

accessing, by the one or more monitoring scripts in the monitoring thread, the monitoring data in the memory after the monitoring data is stored into the memory.

2 . The computer-implemented method of claim 1 , further comprising:

updating the one or more monitoring scripts from a source external of the target process without restarting the target process.

3 . The computer-implemented method of claim 1 , wherein the one or more monitoring scripts identify one or more functions of the target application to monitor and data from the one or more functions to monitor.

4 . The computer-implemented method of claim 1 , wherein the one or more monitoring scripts send monitored data to an agent external of the target process.

5 . A computerized system for modifying a target application executing in a target process including one or more target threads, the computerized system comprising:

memory configured to store executable program code and data; and

at least one hardware processor configured to create a monitoring thread in the target process different than the one or more target threads during runtime of the target process, execute a software engine in the monitoring thread in the target process, during the runtime of the target process, to execute one or more monitoring scripts during the runtime of the target process, wherein the one or more monitoring scripts executing in the monitoring thread are configured to access the memory within the target process and the target application executing in the one or more target threads are configured to access the memory within the target process, modify, by execution of the one or more monitoring scripts, executable code of the target application during the runtime of the target process, wherein the modified executable code is configured to generate monitoring data from the runtime of the target process and to store the monitoring data into the memory during the runtime of the target process, and access, by the one or more monitoring scripts in the monitoring thread, the monitoring data in the memory after the monitoring data is stored into the memory, wherein the at least one hardware processor modifies one or more instructions in a target function of the target application during runtime of the target process to include instructions that call monitoring interceptor code within the one or more monitoring scripts.

6 . The computerized system of claim 5 , wherein the at least one hardware processor further updates the one or more monitoring scripts from a source external of the target process without restarting the target process.

7 . The computerized system of claim 5 , wherein the one or more monitoring scripts identify one or more functions of the target application to monitor and data from the one or more functions to monitor.

8 . The computerized system of claim 5 , wherein the one or more monitoring scripts send monitored data to an agent external of the target process.

9 . One or more tangible non-transitory processor-readable storage media embodied with instructions for executing on one or more processors and circuits of a computing device a process for modifying a target application executing in a target process including one or more target threads, the process comprising:

creating a monitoring thread in the target process different than the one or more target threads during runtime of the target process;

starting execution of a software engine in the monitoring thread in the target process, during the runtime of the target process, to execute one or more monitoring scripts during the runtime of the target process, wherein the one or more monitoring scripts executing in the monitoring thread are configured to access memory within the target process and the target application executing in the one or more target threads are configured to access the memory within the target process;

modifying, by execution of the one or more monitoring scripts, executable code of the target application during the runtime of the target process, wherein the modified executable code is configured to generate monitoring data from the runtime of the target process and to store the monitoring data into the memory during the runtime of the target process, wherein the modifying operation includes modifying one or more instructions in a target function of the target application during runtime of the target process to include instructions that call monitoring interceptor code within the one or more monitoring scripts; and

accessing, by the one or more monitoring scripts in the monitoring thread, the monitoring data in the memory after the monitoring data is stored into the memory.

10 . The one or more tangible non-transitory processor-readable storage media of claim 9 , further comprising:

updating the one or more monitoring scripts from a source external of the target process without restarting the target process.

11 . The one or more tangible non-transitory processor-readable storage media of claim 9 , wherein the one or more monitoring scripts identify one or more functions of the target application to monitor and data from the one or more functions to monitor.

12 . The one or more tangible non-transitory processor-readable storage media of claim 9 , wherein the one or more monitoring scripts send monitored data to an agent external of the target process.

Continuity (4)
Continuation 18464162 · Sep 8, 2023
Continuation 17407034 · Aug 19, 2021
Continuation 16382174 · Apr 11, 2019
Provisional Application 62656308 · Apr 11, 2018
References Cited (33)
US 5978828A · Greer · 1999 [cited by examiner]
US 6819754B1 · Johnson et al. · 2004 [cited by applicant]
US 7356679B1 · Le et al. · 2008 [cited by applicant]
US 7788537B1 · Yellen et al. · 2010 [cited by applicant]
US 8966446B1 · Amacker · 2015 [cited by examiner]
US 9158512B1 · Hucik et al. · 2015 [cited by applicant]
US 9448998B1 · Bluhm · 2016 [cited by applicant]
US 9785489B1 · Chheda · 2017 [cited by examiner]
US 9928107B1 · Mncent · 2018 [cited by applicant]
US 9996761B2 · Chen · 2018 [cited by examiner]
US 11489845B1 · Feng · 2022 [cited by examiner]
US 20030212926A1 · Bhat et al. · 2003 [cited by applicant]
US 20060253580A1 · Dixon et al. · 2006 [cited by applicant]
US 20140053057A1 · Reshadi · 2014 [cited by examiner]
US 20150007251A1 · Johns · 2015 [cited by applicant]
US 20150332043A1 · Russello · 2015 [cited by applicant]
US 20160117159A1 · Balko · 2016 [cited by examiner]
US 20160378611A1 · Ljubuncic et al. · 2016 [cited by applicant]
US 20170026448A1 · Ravindhran et al. · 2017 [cited by applicant]
US 20170046518A1 · Chen et al. · 2017 [cited by applicant]
US 20190034246A1 · Miller et al. · 2019 [cited by applicant]
US 20190068640A1 · Araujo et al. · 2019 [cited by applicant]
CN 1790270A · 2006 [cited by applicant]
CN 105320563A · 2016 [cited by applicant]
CN 105490868A · 2016 [cited by applicant]
KR 1005462200000 · 2006 [cited by applicant]
WO 2014016582A1 · 2014 [cited by applicant]
Malik Khan, A Script-Based Autotuning Compiler System to Generate High-Performance CUDA Cod. (Year: 2013). [cited by examiner]
IBM, AIX Versions 3.2 and 4 Performance Tuning Guide, 2001. [cited by applicant]
Jang, Moonsu , “Detection of DLL inserted by Windows Malicious Code”, 2007. [cited by applicant]
Kim, Hyoung Chun, “JsSandbox: A Framework for Analyzing the Behavior of Malicious JavaScript Code using internal Function Hooking”, 2012. [cited by applicant]
Kulpa, Artur , et al., “Script-based System for Monitoring Client-side Activity”, Business Information Systems, BIS 2006, Conference Paper, Jan. 2006. [cited by applicant]
Tilkov, Stefan , et al., “Node.js: Using JavaScript to build High-Performance Network Programs”, IEEE Computer Society, IEEE Internet Computing, 2010. [cited by applicant]