Patents Assigned to RapidFort, Inc.
-
Patent number: 12602515Abstract: A computer sets an access time for a set of files to an initial value. Upon accessing a file by a set of executables, the computer sets the access time of the file to a new value. The computer identifies, from the set of files, a subset of files accessed by the set of executables based on the access time of files in the subset being different from the initial value. The computer provides an output representing the subset of files.Type: GrantFiled: October 22, 2025Date of Patent: April 14, 2026Assignee: RapidFort, Inc.Inventors: Mehran Farimani, Rajeev Thakur, Chien-Hung Chen
-
Publication number: 20260044631Abstract: A computer sets an access time for a set of files to an initial value. Upon accessing a file by a set of executables, the computer sets the access time of the file to a new value. The computer identifies, from the set of files, a subset of files accessed by the set of executables based on the access time of files in the subset being different from the initial value. The computer provides an output representing the subset of files.Type: ApplicationFiled: October 22, 2025Publication date: February 12, 2026Applicant: RapidFort, Inc.Inventors: Mehran Farimani, Rajeev Thakur, Chien-Hung Chen
-
Patent number: 12411808Abstract: A computing environment determines, by an initialization process, a monitor instance identifier of an instance of an application, wherein the initialization process initializes monitoring of the instance of the application. The computing environment generates, by the initialization process, a system call argument based on a pseudo-randomly generated identifier. The computing environment makes, by the initialization process, a system call comprising the system call argument. The computing environment determines, by a kernel-space Berkeley packet filter (BPF), to monitor the instance of the application based on the system call. The computing environment extracts, by the kernel-space BPF, the pseudo-randomly generated identifier from the system call argument to obtain the monitor instance identifier. The computing environment stores, in a watch list, the monitor instance identifier and the pseudo-randomly generated identifier.Type: GrantFiled: August 15, 2024Date of Patent: September 9, 2025Assignee: RapidFort, Inc.Inventors: Rajeev Thakur, Mehran Farimani, Chien-Hung Chen
-
Patent number: 12380066Abstract: A computing environment determines whether one or more file systems associated with an application allow for modification of a file access time of an associated file and whether a kernel updates, in at least one case, the file access time upon accessing the associated file. The associated file is at least one file managed by the one or more file systems. The computing environment determines files accessed by the application using a technique selected based on whether the one or more file systems allow for modification of the file access time or whether the kernel updates, in the at least one case, the file access time upon accessing the associated file. The computing environment provides an output representing the files accessed by the application.Type: GrantFiled: August 15, 2024Date of Patent: August 5, 2025Assignee: RapidFort, Inc.Inventors: Rajeev Thakur, Mehran Farimani, Chien-Hung Chen
-
Publication number: 20250068599Abstract: A computing environment determines whether one or more file systems associated with an application allow for modification of a file access time of an associated file and whether a kernel updates, in at least one case, the file access time upon accessing the associated file. The associated file is at least one file managed by the one or more file systems. The computing environment determines files accessed by the application using a technique selected based on whether the one or more file systems allow for modification of the file access time or whether the kernel updates, in the at least one case, the file access time upon accessing the associated file. The computing environment provides an output representing the files accessed by the application.Type: ApplicationFiled: August 15, 2024Publication date: February 27, 2025Applicant: RapidFort, Inc.Inventors: Rajeev Thakur, Mehran Farimani, Chien-Hung Chen
-
Publication number: 20250068545Abstract: A computing environment determines, by an initialization process, a monitor instance identifier of an instance of an application, wherein the initialization process initializes monitoring of the instance of the application. The computing environment generates, by the initialization process, a system call argument based on a pseudo-randomly generated identifier. The computing environment makes, by the initialization process, a system call comprising the system call argument. The computing environment determines, by a kernel-space Berkeley packet filter (BPF), to monitor the instance of the application based on the system call. The computing environment extracts, by the kernel-space BPF, the pseudo-randomly generated identifier from the system call argument to obtain the monitor instance identifier. The computing environment stores, in a watch list, the monitor instance identifier and the pseudo-randomly generated identifier.Type: ApplicationFiled: August 15, 2024Publication date: February 27, 2025Applicant: RapidFort, Inc.Inventors: Rajeev Thakur, Mehran Farimani, Chien-Hung Chen
-
Publication number: 20240362365Abstract: A computer sets an access time for a set of files to an initial value. Upon accessing a file by a set of executables, the computer sets the access time of the file to a new value. The computer identifies, from the set of files, a subset of files accessed by the set of executables based on the access time of files in the subset being different from the initial value. The computer provides an output representing the subset of files.Type: ApplicationFiled: April 27, 2023Publication date: October 31, 2024Applicant: RapidFort, Inc.Inventors: Mehran Farimani, Rajeev Thakur, Chien-Hung Chen
-
Patent number: 11360871Abstract: Computer receives, from within system application comprising application(s) that communicate with operating system(s) (OS), selection of target application. Computer creates stub application for target application that mimics entry and exit points of target application. Computer isolates target application externally to system application. Computer establishes network connection(s) connecting isolated target application and stub application to process communication between isolated target application and system application. Computer generates OS tracing system that logs file and directory accesses of isolated target application. Computer monitors runtime behavior of isolated target application, using logs of OS tracing system, to identify files used by target application. Computer determines set of files not used by target application.Type: GrantFiled: November 24, 2020Date of Patent: June 14, 2022Assignee: RapidFort, Inc.Inventors: Mehran Farimani, Rajeev Thakur