IP Library › Granted Patent US 12,650,915
Granted Patent B2
US 12,650,915 · App. 18/701,989 · Granted Jun 9, 2026

Analysis function for suppressing stop of execution due to an exception

Inventors: Toshinori Usui (Musashino, JP); Tomonori Ikuse (Musashino, JP); Yuhei Kawakoya (Musashino, JP); Makoto Iwamura (Musashino, JP)
Assignee: NTT, Inc.
G06F11/3466G06F9/30058G06F9/3865G06F9/45558G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,650,915
App. No.
18/701,989
Granted
Jun 9, 2026
Kind
B2
Abstract

A method includes: acquiring a hook point and a virtual program counter by analyzing a virtual machine of a script engine; acquiring a branch virtual machine instruction by analyzing an instruction set architecture; and providing an analysis function to the script engine based on the acquired virtual program counter and the acquired branch virtual machine instruction, wherein the analysis function is provided by applying a hook to the acquired hook point and wherein the hook includes processing of, in response to an occurrence of an exception, changing a pointing destination of a virtual stack pointer to a return destination of a function immediately before a part where the exception has occurred.

Claims (54)

1 . An analysis function providing method performed by a computer, the analysis function providing method comprising:

acquiring a hook point of a script engine and a virtual program counter by analyzing a virtual machine of the script engine, wherein:

the acquired hook point is a part where an analysis code is inserted by applying a hook; and

the acquired virtual program counter is a variable indicating an instruction of the virtual machine of the script engine to be executed next;

acquiring a branch virtual machine instruction by analyzing an instruction set architecture, wherein:

the instruction set architecture is a system of instructions of the virtual machine of the script engine; and

the acquired branch virtual machine instruction is a virtual machine instruction that causes a branch; and

providing an analysis function to the script engine based on the acquired virtual program counter and the acquired branch virtual machine instruction, wherein the analysis function is executed in the script engine by applying the hook to the acquired hook point of the script engine, and wherein the hook includes processing of, in response to an occurrence of an exception, changing a pointing destination of a virtual stack pointer in a memory to a return destination of a function before a part where the exception has occurred.

2 . The analysis function providing method of claim 1 , wherein;

providing the analysis function includes:

inserting, into a script to be analyzed, an exception handler having a function of transferring processing to a virtual machine area when occurrence of an exception is caught; and

inserting the hook into the acquired hook point of the script engine by using a hook handler including processing of changing the pointing destination of the virtual stack pointer in the memory to the return destination of the function before the pointing destination of the virtual stack pointer in the virtual machine area.

3 . The analysis function providing method of claim 2 , wherein;

analyzing the instruction set architecture includes;

acquiring a virtual machine execution trace that is an execution trace executed in the virtual machine of the script engine, wherein the virtual machine execution trace records a pointer of an executed virtual machine instruction handler in which a virtual machine opcode of the virtual machine execution trace is virtually allocated as an identifier, and the acquired virtual program counter;

acquiring the branch virtual machine instruction includes:

detecting the acquired branch virtual machine instruction by a variation in an amount of change in the acquired virtual program counter for each virtual machine opcode of the virtual machine execution trace; and

the hook handler includes:

first processing of referring to a list of branch virtual machine instructions detected by a detection process, detecting a branch virtual machine instruction from the virtual machine execution trace, and constructing a virtual machine branch trace associated with the acquired virtual program counter before and after execution of the detected branch virtual machine instruction;

second processing of constructing a call stack from the virtual machine branch trace;

third processing of detecting an area of the memory satisfying a predetermined condition regarding commonality with the call stack as a virtual stack, and further detecting an area of the memory pointing to the virtual stack as a virtual stack pointer; and

fourth processing of changing a pointing destination of the virtual stack pointer to a return destination of a function before the pointing destination of the virtual stack pointer.

4 . The analysis function providing method of claim 3 , wherein:

analyzing the virtual machine of the script engine includes;

acquiring a plurality of execution traces while changing a condition at a time of execution;

acquiring the hook point of the script engine includes:

analyzing the execution trace; and

detecting the acquired hook point of the script engine;

acquiring the virtual program counter includes:

clustering the plurality of execution traces to detect a boundary of each virtual machine instruction;

analyzing the plurality of execution traces using differential execution analysis focusing on a number of times of reading the memory and a boundary of each virtual machine instruction detected by a detection process; and

detecting the acquired virtual program counter; and

wherein the analysis function providing method further comprises:

analyzing a binary of the script engine; and

detecting a dispatcher on the basis of a boundary of each virtual machine instruction detected by the detection process.

5 . The analysis function providing method of claim 1 , further comprising performing the analysis function using a test script.

6 . An analysis function providing device comprising:

a memory; and

a processor coupled to the memory and configured to perform operations comprising:

acquiring a hook point of a script engine and a virtual program counter by analyzing a virtual machine of the script engine, wherein:

the acquired hook point is a part where an analysis code is inserted by applying a hook; and

the acquired virtual program counter is a variable indicating an instruction of the virtual machine of the script engine to be executed next;

acquiring a branch virtual machine instruction by analyzing an instruction set architecture, wherein:

the instruction set architecture is a system of instructions of the virtual machine of the script engine; and

the acquired branch virtual machine instruction is a virtual machine instruction that causes a branch; and

providing an analysis function to the script engine based on the acquired virtual program counter and the acquired branch virtual machine instruction, wherein the analysis function is executed in the script engine by applying the hook to the acquired hook point of the script engine, and wherein the hook includes processing of, in response to an occurrence of an exception, changing a pointing destination of a virtual stack pointer in a memory to a return destination of a function before a part where the exception has occurred.

7 . A non-transitory computer readable storage medium having an analysis function providing program stored thereon that, when executed by a processor, causes the processor to perform operations comprising:

acquiring a hook point of a script engine and a virtual program counter by analyzing a virtual machine of the script engine, wherein:

the acquired hook point is a part where an analysis code is inserted by applying a hook; and

the acquired virtual program counter is a variable indicating an instruction of the virtual machine of the script engine to be executed next;

acquiring a branch virtual machine instruction by analyzing an instruction set architecture, wherein:

the instruction set architecture is a system of instructions of the virtual machine of the script engine; and

the acquired branch virtual machine instruction is a virtual machine instruction that causes a branch; and

providing an analysis function to the script engine based on the acquired virtual program counter and the acquired branch virtual machine instruction, wherein the analysis function is executed in the script engine by applying the hook to the acquired hook point of the script engine, and wherein the hook includes processing of, in response to an occurrence of an exception, changing a pointing destination of a virtual stack pointer in a memory to a return destination of a function before a part where the exception has occurred.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2024
From: USUI, TOSHINORI; IKUSE, TOMONORI; KAWAKOYA, YUHEI; IWAMURA, MAKOTO
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 067132/0934 →
Continuity (1)
Related Publication 20240411557A1 · Dec 12, 2024
References Cited (10)
US 11010280B1 · Stupachenko · 2021 [cited by examiner]
US 20100153776A1 · Vick · 2010 [cited by examiner]
US 20150121135A1 · Pape · 2015 [cited by examiner]
US 20170262387A1 · Sell · 2017 [cited by examiner]
Saxena et al., “A Symbolic Execution Framework for JavaScript”, 2010 IEEE Symposium on Security and Privacy, May 16-19, 2010, pp. 513-528. [cited by applicant]
Kim et al., “J-Force: Forced Execution on JavaScript”, 2017 International World Wide Web Conference Committee (IW3C2), Apr. 3-7, 2017, pp. 897-906. [cited by applicant]
Bucur et al., “Prototyping Symbolic Execution Engines for Interpreted Languages”, School of Computer and Communication Sciences, Feb. 24, 2014, 108 pages. [cited by applicant]
Sharif et al., “Automatic Reverse Engineering of Malware Emulators”, 2009 30th IEEE Symposium on Security and Privacy, May 17-20, 2009, pp. 94-109. [cited by applicant]
Usui et al., “Automatically Appending Multi-Path Execution Functionality to Vanilla Script Engines”, CSS 2019 Conference, 8 pages including English Abstract. [cited by applicant]
Kolbitsch et al., “The Power of Procrastination: Detection and Mitigation of Execution-Stalling Malicious Code”, CSS'11, Oct. 17-21, 2011, pp. 285-296. [cited by applicant]