IP Library Granted Patent US 9,400,889
Granted Patent B2
US 9,400,889 · App. 11/733,169 · Granted Jul 26, 2016

Apparatus and method for developing secure software

Inventors: Brian Chess (Mountain View, CA); Arthur Do (Danville, CA); Sean Fay (San Francisco, CA); Roger Thornton (San Jose, CA)
Assignee: Hewlett Packard Enterprise Development LP
G06F21/577G06F11/3612
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,400,889
App. No.
11/733,169
Granted
Jul 26, 2016
Kind
B2
Abstract

A computer readable medium includes executable instructions to analyze program instructions for security vulnerabilities. The executable instructions convert diverse program instruction formats to a common format. A system model is derived from the common format. A static analysis is performed on the system model to identify security vulnerabilities. Security vulnerabilities are then reported.

Claims (31)

1. A processor-readable non-transitory medium comprising code representing instructions that when executed at a hardware processor cause the hardware processor to:

convert diverse program instruction formats to a common format;

derive a system model from said common format;

perform a static analysis on said system model using a number of custom detection mechanisms to dynamically identify security vulnerabilities;

insert a sensor into the program instructions at runtime, wherein the sensor applies a set of event processing rules;

and

execute the sensor to identify a type of attack to which an application associated with the program instructions is susceptible based on the executable instructions and the dynamically identified security vulnerabilities by comparing contextual data relevant to an event to the set of event processing rules and in the case of a match, passing the event to a transceiver for logging and reporting.

2. The computer readable medium of claim 1 wherein said executed instructions to convert include executed instructions to convert different source or executable code formats executing on different platforms to said common format.

3. The computer readable medium of claim 1 wherein said executed instructions to convert include executed instructions to convert different machine instruction formats to said common format.

4. The computer readable medium of claim 1 wherein said executed instructions to convert include executed instructions to convert different program configuration file formats to said common format.

5. The computer readable medium of claim 1 wherein said executed instructions to convert include executed instructions to convert a program instruction expression into an equivalent sequence of simpler statements defined in said common format.

6. The computer readable medium of claim 5 wherein said executed instructions to convert include executed instructions to convert said program instruction expression into an equivalent sequence of simpler statements that includes a temporary variable.

7. The computer readable medium of claim 1 wherein said executed instruction to derive include executed instructions to derive a system model characterizing multiple interoperative applications.

8. The computer readable medium of claim 1 wherein said executed instructions to perform include executed instructions to identify locations where input is taken from outside the program instruction formats.

9. The computer readable medium of claim 8 wherein said executed instructions to perform include executed instructions to trace the processing of said input throughout said diverse program instruction formats.

10. The computer readable medium of claim 1 wherein said executed instructions to perform include executed instructions to identify at least one of the following security vulnerabilities: stack buffer overflow, heap buffer overflow, format string attack, SQL injection, an ordering problem, and protocol misuse.

11. The computer readable medium of claim 1 wherein said executed instructions to perform a static analysis include executed instructions to perform a static analysis selected from a static data flow analysis, a lexical analysis, a semantic analysis, and a program control flow analysis.

12. The computer readable medium of claim 1 wherein said executed instructions to report include executed instructions to report a vulnerability, a vulnerability entry point, and a vulnerability processing path.

13. The computer readable medium of claim 1 wherein said executed instructions to report include executed instructions to report said security vulnerabilities and said type of attack to a security test module and a security monitoring module.

14. A method of analyzing program instructions for security vulnerabilities implemented by a physical processor executing computer-readable instructions, the method, comprising:

converting, by the processor, diverse program instruction formats to a common format;

deriving, by the processor, a system model from said common format;

performing, by the processor, a static analysis on said system model using a number of custom detection mechanisms to dynamically identify security vulnerabilities;

inserting, by the processor, a sensor into the program instructions at runtime, wherein the sensor applies a set of event processing rules; and

executing the sensor to identify, performance criteria associated with the program instructions by comparing contextual data relevant to an event to the set of event processing rules and in the case of a match, passing the event to a transceiver for logging and reporting.

15. The method of claim 14 wherein converting includes converting different source or executable code formats executing on different platforms to said common format.

16. The method of claim 14 wherein converting includes converting different machine instruction formats to said common format.

17. The method of claim 14 wherein converting includes converting different program configuration file formats to said common format.

18. The method of claim 14 wherein converting includes converting a program instruction expression into an equivalent sequence of simpler statements defined in said common format.

19. The method of claim 14 wherein deriving includes deriving a system model characterizing multiple inter-operative applications.

20. The method of claim 14 wherein performing a static analysis includes performing a static analysis selected from a static data flow analysis, a lexical analysis, a semantic analysis, and a program control flow analysis.

Assignments (11)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: HEWLETT-PACKARD SOFTWARE, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029316/0280 →
MERGER Recorded Nov 16, 2012
From: FORTIFY SOFTWARE, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029316/0274 →
CERTIFICATE OF CONVERSION Recorded Apr 20, 2011
From: FORTIFY SOFTWARE, INC.
To: FORTIFY SOFTWARE, LLC
Reel/Frame 026155/0089 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2007
From: CHESS, BRIAN; DO, ARTHUR; FAY, SEAN; THORNTON, ROGER
To: FORTIFY SOFTWARE, INC.
Reel/Frame 019137/0354 →
Continuity (3)
Continuation 11010146 · Dec 10, 2004
Provisional Application 60577066 · Jun 4, 2004
Related Publication 20070240138A1 · Oct 11, 2007