IP Library Granted Patent US 7,207,065
Granted Patent B2
US 7,207,065 · App. 11/010,146 · Granted Apr 17, 2007

Apparatus and method for developing secure software

Assignee: Fortify Software, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,207,065
App. No.
11/010,146
Filed
Dec 10, 2004
Granted
Apr 17, 2007
Kind
B2
Examiner
ZAND, KAMBIZ
Art Unit
2132
USPC
726/25
Abstract

A computer readable medium includes executable instructions to analyze program instructions for security vulnerabilities. The executable instructions convert diverse program instruction formats to a common format. A system model is derived from the common format. A static analysis is performed on the system model to identify security vulnerabilities. Security vulnerabilities are then reported.

Claims (28)

1. A computer readable medium including stored executable instructions to analyze program instructions for security vulnerabilities, comprising instructions executing to:

convert diverse program instruction formats of a set of software applications executing on different platforms to a common format, wherein said executable instructions to convert include executable instructions to break down expressions of said diverse program instruction formats into a single set of equivalent sequences of simpler statements to support analysis of said diverse program instruction formats;

derive a system model from said common format, wherein said model characterizes program interactions between said diverse program instruction formats;

perform a static analysis on said system model to identify security vulnerabilities, wherein said static analysis includes analyzing said system model without executing said system model; and

report said security vulnerabilities.

2. The computer readable medium of claim 1 wherein said executable instructions to convert include executable instructions to convert different source or executable code formats executing on different platforms to said common format.

3. The computer readable medium of claim 1 wherein said executable instructions to convert include executable instructions to convert different machine instruction formats to said common format.

4. The computer readable medium of claim 1 wherein said executable instructions to convert include executable instructions to convert different program configuration file formats to said common format.

5. The computer readable medium of claim 1 wherein said executable instructions to convert include executable instructions to convert a program instruction expression into an equivalent sequence of simpler statements defined in said common format.

6. The computer readable medium of claim 5 wherein said executable instructions to convert include executable instructions to convert said program instruction expression into an equivalent sequence of simpler statements that includes a temporary variable.

7. The computer readable medium of claim 1 wherein said executable instruction to derive include executable instructions to derive a system model characterizing multiple inter-operative applications.

8. The computer readable medium of claim 1 wherein said executable instructions to perform include executable instructions to identify locations where input is taken from outside the program instruction formats.

9. The computer readable medium of claim 8 wherein said executable instructions to perform include executable instructions to trace the processing of said input throughout said diverse program instruction formats.

10. The computer readable medium of claim 1 wherein said executable instructions to perform include executable instructions to identify at least one of the following security vulnerabilities: stack buffer overflow, heap buffer overflow, format string attack, SQL injection, an ordering problem, and protocol misuse.

11. The computer readable medium of claim 1 wherein said executable instructions to perform a static analysis include executable instructions to perform a static analysis selected from a static data flow analysis, a lexical analysis, a semantic analysis, and a program control flow analysis.

12. The computer readable medium of claim 1 wherein said executable instructions to report include executable instructions to report a vulnerability, a vulnerability entry point, and a vulnerability processing path.

13. The computer readable medium of claim 1 wherein said executable instructions to report include executable instructions to report said security vulnerabilities to a security test module and a security monitoring module.

14. A method of analyzing stored program instructions for security vulnerabilities, comprising:

converting diverse program instruction formats of a set of software applications executing on different platforms to a common format, wherein converting includes breaking down expressions of said diverse program instruction formats into a single set of equivalent sequences of simpler statements to support analysis of said diverse program instruction formats;

deriving a system model from said common format, wherein said system model characterizes program interactions between said diverse program instruction formats;

performing a static analysis on said system model to identify security vulnerabilities, wherein said static analysis includes analyzing said system model without executing said system model; and

reporting said security vulnerabilities.

15. The method of claim 14 wherein converting includes converting different source or executable code formats executing on different platforms to said common format.

16. The method of claim 14 wherein converting includes converting different machine instruction formats to said common format.

17. The method of claim 14 wherein converting includes converting different program configuration file formats to said common format.

18. The method of claim 14 wherein converting includes converting a program instruction expression into an equivalent sequence of simpler statements defined in said common format.

19. The method of claim 14 wherein deriving includes deriving a system model characterizing multiple inter-operative applications.

20. The method of claim 14 wherein performing a static analysis includes performing a static analysis selected from a static data flow analysis, a lexical analysis, a semantic analysis, and a program control flow analysis.

Assignments (12)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
MERGER Recorded Nov 16, 2012
From: FORTIFY SOFTWARE, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029316/0274 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: HEWLETT-PACKARD SOFTWARE, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029316/0280 →
CERTIFICATE OF CONVERSION Recorded Apr 20, 2011
From: FORTIFY SOFTWARE, INC.
To: FORTIFY SOFTWARE, LLC
Reel/Frame 026155/0089 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2004
From: CHESS, BRIAN; DO, ARTHUR; FAY, SEAN; THORNTON, ROGER
To: FORTIFY SOFTWARE, INC.
Reel/Frame 016260/0538 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2004
From: CHESS, BRIAN; DO, ARTHUR; FAY, SEAN; THORNTON, ROGER
To: FORTIFY SOFTWARE, INC.
Reel/Frame 016259/0994 →
Continuity (2)
Provisional Application 6057706600 · Jun 4, 2004
Related Publication 20050273854A1 · Dec 8, 2005