Invention Grant
- Patent Title: System and method for generating a file execution record of address tuples
-
Application No.: US15657239Application Date: 2017-07-24
-
Publication No.: US11615338B2Publication Date: 2023-03-28
- Inventor: Maor Hizkiev , Liron Barak , Alex Livshiz , Ran Regenstreif
- Applicant: BITDAM LTD
- Applicant Address: IL Netanya
- Assignee: BITDAM LTD
- Current Assignee: BITDAM LTD
- Current Assignee Address: IL Netanya
- Agency: Maschoff Brennan
- Main IPC: G06N20/00
- IPC: G06N20/00 ; G06F21/51 ; G06F21/56 ; G06F16/22 ; G06F16/951

Abstract:
A system and method generating a database of tuple addresses associated with a computer program, the method comprising fetching from a repository of sample files a sample file suitable for running by the computer program, and performing dynamic learning of the sample file to obtain tuple addresses used by the computer program in loading of the sample file, the dynamic learning comprising while loading of the sample file by the computer program, monitoring loaded processes and modules, for each loaded process, tracing process branches, upon identification of a mispredicted branch, getting an address tuple of the mispredicted branch, and identifying a module to which the tuple belongs based on the module's base address.
Public/Granted literature
- US20190026649A1 SYSTEM AND METHOD FOR GENERATING A FILE EXECUTION RECORD OF ADDRESS TUPLES Public/Granted day:2019-01-24
Information query