IP Library Granted Patent US 10,025,691
Granted Patent B1
US 10,025,691 · App. 15/261,327 · Granted Jul 17, 2018

Verification of complex software code using a modularized architecture

Inventors: Osman Abdoul Ismael (Palo Alto, CA); Hendrik Tews (Dresden, DE); Ashar Aziz (Coral Gables, FL)
Assignee: FireEye, Inc.
G06F11/3608G06F9/45558G06F21/566G06F21/577G06F21/6218G06F2009/45587G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,025,691
App. No.
15/261,327
Granted
Jul 17, 2018
Kind
B1
Abstract

A technique verifies a compound software code using a modularized architecture. The compound software code may be divided into smaller components or modules that provide various functions (e.g., services) of the code. A set of properties may be defined for the modules, such that the verification technique may be used to verify that the modules manifest those properties, wherein at least one property may be security related and the remaining properties may be related to the services of the modules. The compound software code is divided into smaller modules to facilitate verification of the properties related to the services provided by the modules. Properties of the modules may be verified in accordance with an enhanced verification procedure to demonstrate that the modules manifest those properties and transform those modules into verified code bases (VCBs). The services of the VCBs may then be combined to provide functionality of the compound software code using well-defined interfaces, such as application programming interfaces (APIs).

Claims (34)

1. A method comprising:

storing a compound software code in a memory connect to a central processing unit (CPU) adapted to execute the compound software code, the compound software code being divided into modules;

verifying that the compound software code implements a first property by verifying one or more second properties of the modules using an enhanced verification procedure to demonstrate that the modules manifest the one or more second properties and to transform the modules into verified code bases (VCBs), each VCB having an operational model, the enhanced verification procedure including (i) generating an executable of the operational model of a corresponding VCB, (ii) capturing a state dump of the executable of the operational model, (iii) capturing a corresponding state dump of an executable of the corresponding VCB, and (iv) iteratively comparing states of the executable of the operational model and the executable of the corresponding VCB until a predetermined number of the states match, wherein the predetermined number of matched states correspond to a predetermined level of confidence that a respective second property is implemented by the corresponding VCB; and

executing services of the VCBs on the CPU in combination to provide functionality of the compound software code using interfaces.

2. The method of claim 1 wherein verifying the one or more second properties comprises:

executing the operational model in a functional programming language.

3. The method of claim 1 wherein the one or more second properties of the modules are subordinate properties that include at least one security related property and one or more service related second properties of the VCBs.

4. The method of claim 1 wherein the interfaces are application programming interfaces (APIs) and wherein verifying the one or more second properties of the modules includes verifying the APIs of the VCBs.

5. The method of claim 4 wherein executing the combined services of the VCBs comprises:

communicating with one of a trusted code base (TCB) and other VCBs using the verified APIs and an additional API of the TCB, wherein the VCBs are disposed over the TCB.

6. The method of claim 1 wherein each VCB has size of lines of software code that enables verification of the respective second property using the enhanced verification procedure.

7. The method of claim 5 wherein

the VCBs are organized as one or more groups according to the verified properties and wherein one or more of the verified APIs of each group of VCBs are exposed to invoke services of a respective group of VCBs.

8. The method of claim 7 wherein a verified set of second properties of a first group is different from the verified set of second properties of a second group.

9. A system comprising:

a central processing unit (CPU) configured to execute a compound software code divided into modules; and

a memory configured to store the modules, the compound software code verified to implement a first property by an enhanced verification to demonstrate that the modules manifest one or more second properties to transform the modules into verified code bases (VCBs), each VCB having an operational model, the services of the VCBs combined to provide functionality of the compound software code using interfaces, the enhanced verification configured to:

generate an executable of the operational model of a corresponding VCB;

capture a state dump of the executable of the operational model;

capture a corresponding state dump of an executable of the corresponding VCB; and

iteratively compare states of the executable of the operational model and the executable of the corresponding VCB until a predetermined number of the states match, wherein the predetermined number of matched states correspond to a predetermined level of confidence that a respective second property is implemented by the corresponding VCB.

10. The system of claim 9 wherein the executable of the operational model is executed in a functional programming language.

11. The system of claim 9 wherein the one or more second properties are subordinate properties that include at least one security related property and one or more service related second properties of the VCBs.

12. The system of claim 9 wherein the interfaces are application programming interfaces (APIs) and wherein the enhanced verification further verifies the APIs of the VCBs.

13. The system of claim 12 wherein the VCBs are disposed over a trusted code base (TCB) in a configuration that enables communication with one of the TCB and the VCBs using the verified APIs and an additional API of the TCB.

14. The system of claim 13 wherein each VCB has a size of lines of software code that enables the enhanced verification of the respective second property.

15. The system of claim 14 wherein the VCBs are organized as one or more groups according to verified second properties.

16. The system of claim 13 wherein the verified APIs implement one or more third properties subordinate to the one or more second properties.

17. The system of claim 15 wherein the verified second properties of a first group are different from the verified second properties of a second group.

18. A non-transitory computer readable medium including program instructions for execution on a processor of a node on a network, the program instructions divided into modules configured to:

execute services using interfaces, wherein the program instructions are verified to implement a first property by verifying second properties of the modules using an enhanced verification procedure to demonstrate that the modules manifest the properties to transform the modules into verified code bases (VCBs), each VCB having an operational model, the enhanced verification procedure including (i) generating an executable of the operational model of a corresponding VCB, (ii) capturing a state dump of the executable operational model, (iii) capturing a corresponding state dump of an executable of the corresponding VCB, and (iv) iteratively comparing states of the executable of the operational model and the executable of the corresponding VCB until a predetermined number of the states match, wherein the predetermined number of matched states correspond to a predetermined level of confidence that the second property is implemented by the corresponding VCB; and

combine the services of the VCBs to provide functionality of the program instructions using the interfaces.

19. The non-transitory computer readable medium of claim 18 wherein the respective executable of the operational model is executed in a functional programming language.

20. The non-transitory computer readable medium of claim 18 wherein the interfaces are application programming interfaces (APIs) and wherein the enhanced verification procedure further verifies the APIs of the VCBs.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063272/0743 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063113/0029 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2016
From: ISMAEL, OSMAN ABDOUL; TEWS, HENDRIK; AZIZ, ASHAR
To: FIREEYE, INC.
Reel/Frame 039691/0195 →
Cited By (10)
US 12,200,013 US 12,248,563 US 12,259,978 US 12,278,834 US 12,348,561 US 12,363,145 US 12,388,865 US 12,445,458 US 12,445,481 US 12,663,999