The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 08, 2022

Filed:

Jun. 25, 2021
Applicant:

Oracle International Corporation, Redwood Shores, CA (US);

Inventors:

Kostyantyn Vorobyov, Brisbane, AU;

François Gauthier, Brisbane, AU;

Sora Bae, Carindale, AU;

Padmanabhan Krishnan, Brisbane, AU;

Assignee:

Oracle International Corporation, Redwood Shores, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/563 (2013.01); G06F 21/562 (2013.01); G06F 21/566 (2013.01); G06F 2221/033 (2013.01);
Abstract

A method for detecting malicious code may include generating, from deserialization examples, a finite automaton including states. The states may include labeled states corresponding to the deserialization examples. A state may correspond to a path from a start state to the state. The method may further include while traversing the states, generating a state mapping including, for the state, a tracked subset of the states, determining that the path corresponds to a path type, inferring, using the path type and the state mapping, a regular expression for the state, and determining, for a new deserialization example and using the regular expression, a polarity indicating whether it is safe to deserialize the new deserialization example.


Find Patent Forward Citations

Loading…