Abstract: A system of determining a software bill-of-materials (RBOM) of an operating environment, the system comprising a processing circuitry configured to: a) access a memory space of a first process executing in the operating environment; b) for one or more threads of the first process: read contents of one or more memory location of a thread stack associated with the respective thread, determine whether a contained value of a respective memory location is a code section execution address, and responsive to the contained value of the respective memory location of the thread stack being a code section execution address: i) determine, based on the memory space of the first process and/or an executable file associated with the first process, a code section identifier associated with the code section, and ii) add the code section identifier associated with the code section to the RBOM.
Type:
Grant
Filed:
April 15, 2024
Date of Patent:
June 2, 2026
Assignee:
Kodem Security Ltd.
Inventors:
Eran Segal, Moshe Siman Tov Bustan, Pavel Furman, Idan Bartura, Aviv Mussinger
Abstract: There is provided a computer system of runtime identification of a dynamic loading of a software module, the software module being associated with a first application framework, the system comprising a processing circuitry configured to: a) detect, in a first interposition function, an invocation of a first function, the first function being associated with loading of software-modules within a first application framework; b) identify a software-module being loaded, the identifying utilizing, at least, at least one of: i) parameter data supplied in the invocation of the first function, ii) a context of an operating system process invoking the first function, and ii) data that was stored responsive to detecting, by a respective interposition function, one or more prior invocations of respective functions associated with loading of software-modules within the first application framework; and c) add the identified software-module to a list of software-modules.
Type:
Grant
Filed:
July 18, 2022
Date of Patent:
May 21, 2024
Assignee:
KODEM SECURITY LTD.
Inventors:
Pavel Furman, Idan Bartura, Aviv Mussinger