Abstract: Methods of collecting data from one or more exploits or attacks by cybercriminals or hackers without the use of so-called honey traps, thereby obtaining valuable forensic data without the maintenance and inefficiencies of inserting honey traps in code, such as firmware executing on IoT devices, is described. Specialized code written or adapted by a service provider is inserted into the firmware on whatever device a legitimate entity wants to protect and believes is open to exploitation or attack. Once the specialized code as been inserted, the firmware on the device is able to detect whether it is being exploited or attacked. If the device is being exploited, the specialized code determines if the exploit is known or is a new exploit. The firmware collects forensic data resulting from the exploit. This collection of forensic data is done without the cybercriminal or hacker's knowledge.
Abstract: A novel compiler is described. The compiler is able to view source code of the application in its entirety and can do so from the inside. Unlike other tools which examine the forensic data from an application crash after the fact, from the outside, the compiler of the present invention can provide novel data on function call stacks and function profiles during runtime. The application may be stopped immediately during runtime to prevent further or potential damage, but the forensic data that is collected is focused and can be used to show where vulnerabilities exists in the application and how they were exploited. Hashes are taken of function call stacks and used as unique identifiers or thumbprints which can be used to reduce the volume of forensic data that needs to be analyzed after an attack.
Type:
Grant
Filed:
December 20, 2022
Date of Patent:
March 5, 2024
Assignee:
Dellfer, Inc.
Inventors:
Brian H. Pescatore, James Blaisdell, Xonia Ivonne McLaughlin, Chetin Ersoy, Kenneth J. Wante
Abstract: A novel compiler is described. The compiler is able to view source code of the application in its entirety and can do so from the inside. Unlike other tools which examine the forensic data from an application crash after the fact, from the outside, the compiler of the present invention can provide novel data on function call stacks and function profiles during runtime. The application may be stopped immediately during runtime to prevent further or potential damage, but the forensic data that is collected is focused and can be used to show where vulnerabilities exists in the application and how they were exploited. Hashes are taken of function call stacks and used as unique identifiers or thumbprints which can be used to reduce the volume of forensic data that needs to be analyzed after an attack.
Type:
Grant
Filed:
August 14, 2020
Date of Patent:
June 27, 2023
Assignee:
Dellfer, Inc.
Inventors:
Brian H. Pescatore, James Blaisdell, Xonia Ivonne McLaughlin, Chetin Ersoy, Kenneth J. Wante