Non-Invasive API Discovery via Memory and Runtime Signal Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity methods, such as eBPF or instrumentation-based techniques, are not feasible for environments where direct instrumentation or modification of compiled APIs, legacy systems, and enterprise-grade applications is not viable, necessitating a non-invasive approach for API discovery, monitoring, and exploitation detection.
Innovation Solution
A non-invasive methodology that scans memory, monitors opened streams and file descriptors, and analyzes runtime signals to discover APIs, detect sensitive credentials, and monitor for exploitation attempts without disrupting the process, integrating with existing security systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional instrumentation-based methods (eBPF, probes) are used for API discovery and monitoring, then detection capability is improved, but applicability deteriorates because these methods require direct instrumentation or modification of the process
Solution Approach 1:
The patent uses file descriptors and streams as intermediary objects to indirectly monitor process behavior. Instead of instrumenting the process directly, the system monitors file descriptors opened by the process, which serve as mediators between the monitoring system and the target process, enabling observation without direct intervention
Solution Approach 2:
The patent replaces mechanical instrumentation approaches (probes, eBPF hooks) with memory scanning and pattern recognition techniques. Instead of mechanically inserting monitoring code into the process, the system scans process memory for API function pointers and credentials using pattern matching, substituting physical instrumentation with computational analysis
2Measurement precision
If memory scanning and runtime analysis are performed continuously, then detection accuracy is improved, but performance overhead worsens
Solution Approach 1:
The patent implements periodic sampling of process memory and file descriptor states rather than continuous monitoring. The system performs memory scans and file descriptor analyses at intervals, allowing the monitored process to run between scans with minimal interference, thus reducing performance overhead while maintaining detection accuracy
Solution Approach 2:
The patent focuses monitoring efforts on specific critical areas (API function pointers, credential strings, file descriptor states) rather than analyzing all process memory and operations. This partial action approach concentrates computational resources on high-value targets, improving detection accuracy without proportionally increasing overall performance overhead
3Measurement precision
If comprehensive memory scanning is performed to detect credentials and APIs, then detection completeness is improved, but system complexity worsens
Solution Approach 1:
The patent segments the memory scanning process into distinct phases: identifying API function pointers by scanning for known function names, extracting credentials by searching for credential patterns in memory, and analyzing file descriptors separately. This segmentation breaks down the complex task of comprehensive monitoring into manageable, independent modules that can be implemented and maintained more easily
Data Source
AI summary
System and method for non-invasive monitoring and exploitation detection in third-party software processes. The system includes modules for scanning process memory to identify sensitive credentials such as application programming interface (API) keys and tokens, monitoring opened file descriptors including files, sockets, and inter-process communication channels, and analyzing network activity including domain name system (DNS) requests and encrypted connections. Runtime metadata such as privileges, environment variables and resource usage is also collected. The system correlates these signals to detect indicators of exploitation, such as unauthorized access, privilege escalation, or injected payloads, without modifying or instrumenting the monitored process. Integration with external security systems may enhance detection accuracy. Alerts and reports are generated in real-time to support incident response and forensic analysis.


