IP Library Granted Patent US 10,740,470
Granted Patent B2
US 10,740,470 · App. 15/994,076 · Granted Aug 11, 2020

System and method for application security profiling

Inventors: Vlad A Ionescu (Santa Clara, CA); Fabian Yamaguchi (Santa Clara, CA); Chetan Conikee (Santa Clara, CA); Manish Gupta (Santa Clara, CA)
Assignee: Shiftleft Inc.
G06F21/577G06F21/563G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,740,470
App. No.
15/994,076
Granted
Aug 11, 2020
Kind
B2
Abstract

A system and method for application security profiling that includes extracting a code property graph from at least a subset of a code base; generating a code profile from the code property graph, wherein generating the code profile occurs prior to a compilation of the code base; and applying the code profile, comprising of identifying sections of interest within the code base.

Claims (44)

1. A method for application security profiling comprising of:

creating a code policy, wherein the policy is a formal specification for generating a code profile;

extracting a code property graph from at least a subset of a code base, wherein extracting the code property graph comprises of:

extracting an abstract syntax tree subcomponent,

extracting a control flow graph subcomponent,

extracting a property graph subcomponent, and

forming a joint data structure of the three subcomponents such that each subcomponent has a node for each subject and predicate of the base code;

generating a code profile from the code property graph and the code policy, thereby:

identifying interface channels, wherein interface channels characterize input/output associated operations of the code base,

classifying data types and functions,

characterizing code based dependencies, by tracing a flow of data using a data flow graph,

characterizing exposed interfaces of the code base, by tracing the flow of interfaces using the control flow graph, and

wherein generating the code profile occurs prior to a compilation of the code base; and

applying the code profile, comprising of identifying sections of interest within the code base.

2. The method of claim 1 , wherein extracting the code property graph further comprises of initially extracting the abstract syntax tree subcomponent, the control flow graph subcomponent, and the data flow graph subcomponent from the code base.

3. The method of claim 1 , wherein extracting the code property graph further comprises of maintaining the code property graph with changes to the code base.

4. The method of claim 1 , wherein creating the code policy comprises of receiving user input specifying at least a portion of the code policy.

5. The method of claim 1 , wherein creating the code policy comprises of iteratively applying an application security profiling method to the code base.

6. The method of claim 5 , wherein iteratively applying the method comprises of applying the method to lower level dependencies of the code base.

7. The method of claim 1 , wherein classifying data types comprises of classifying sensitive data.

8. The method of claim 1 , wherein classifying data types comprises of classifying attacker controlled data and unvalidated user data.

9. The method of claim 1 , wherein generating the code profile further comprises of traversing the code profile graph and identifying flows between various points of the code base.

10. The method of claim 1 , wherein extracting a code property graph further comprises of extracting a code property graph from a subset of multiple code bases.

11. The method of claim 10 , wherein generating a code profile further comprises of generating a code profile for a subset of multiple code bases.

12. The method of claim 1 , wherein extracting a code property graph further comprises parallelizing computation of the code property graph across multiple computational nodes.

13. The method of claim 1 , wherein applying the code profile occurs prior to application runtime.

14. The method of claim 1 , wherein applying the code profile further comprises of generating a code profile report.

15. The method of claim 1 , wherein applying the code profile further comprises of augmenting the development process of the code base by implementing code specific recommendations from the code profile.

16. The method of claim 1 , wherein applying the code profile further comprises of implementing a dynamic code-specific runtime agent.

17. A method for application security profiling comprising of:

creating a code policy, wherein the code policy is a formal specification for generating a code profile;

extracting a code property graph from a subset of a code base, wherein extracting a code property graph comprises of:

extracting an abstract syntax tree subcomponent,

extracting a control flow graph subcomponent,

extracting a property graph subcomponent, and

forming a joint data structure of the three subcomponents such that each subcomponent has a node for each subject and predicate of the code base;

generating the code profile, by traversing the code property graph and using the code policy, thereby:

identifying interface channels, wherein interface channels characterize input/output associated operations of the code base,

classifying data types and functions,

characterizing code based dependencies, by tracing a flow of data using a data flow graph,

characterizing exposed interfaces of the code base, by tracing the flow of interfaces using the control flow graph, and

wherein generating the code profile occurs prior to a compilation of the code base; and

applying the code profile, comprising of identifying locations of interest within the code base.

18. The method of claim 17 , wherein generating the code profile further comprises of implementing specifications of the code policy into at least one of the code profile subcomponents, thereby generating a code profile that comprises of subcomponents and flow interactions of interest.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2026
From: SHIFTLEFT, INC.
To: HARNESS INC.
Reel/Frame 074196/0845 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2018
From: IONESCU, VLAD A; CONIKEE, CHETAN; GUPTA, MANISH; YAMAGUCHI, FABIAN
To: SHIFTLEFT INC
Reel/Frame 045956/0539 →
Continuity (2)
Provisional Application 62512728 · May 31, 2017
Related Publication 20180349614A1 · Dec 6, 2018
Cited By (11)
US 12,229,264 US 12,287,906 US 12,299,502 US 12,307,305 US 12,386,684 US 12,401,694 US 12,405,948 US 12,437,057 US 12,498,998 US 12,663,987 US 12,693,839