IP Library Granted Patent US 11,748,489
Granted Patent B2
US 11,748,489 · App. 17/221,109 · Granted Sep 5, 2023

Unified software library access and vulnerability correction prioritization

Inventors: Tamilarasan Janakiraman (Hosur, IN); Kannan Subbaraman (Bangalore, IN); Vijayasarathy Vajravel (Bangalore, IN)
Assignee: Dell Products, L.P.
G06F21/577G06F9/45558G06F2009/45579G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,748,489
App. No.
17/221,109
Filed
Apr 2, 2021
Granted
Sep 5, 2023
Kind
B2
Art Unit
2438
USPC
726/25
Abstract

A container-based software implementation uses separate containers for software libraries and application code. A storage system may have multiple applications executing to control various aspects of operation of the storage system, and to enable access to the storage system by hosts. These applications are containerized separately from the libraries referenced by the applications, and the libraries are commonly housed in a separate container. The libraries may be open-source libraries, proprietary libraries, or third-party dependent libraries. A vulnerability management system scans the application containers to determine dependencies between applications and libraries, including the number of containers that reference a particular library and the frequency with which microservices of the containerized application reference the library. A vulnerability prioritization system uses the determined dependencies and vulnerability severity scores to prioritize libraries for correction based on the frequency of use of the library, the number of products impacted, and the severity of the vulnerabilities.

Claims (27)

1. A non-transitory tangible computer readable storage medium having stored thereon a computer program for implementing a method of unifying software library access and prioritizing software library-based vulnerabilities for correction, the computer program including a set of instructions which, when executed by a computer, cause the computer to perform the steps of:

creating a shared library container by a containerization process, the shared library container containing a set of libraries but not executable application code;

creating a set of application containers by the containerization process, wherein each application container is an independent container, separate from the shared library container, and contains one or more applications implemented as executable application code for execution on an operating system of a storage system and configuration files, but not any library of the set of libraries that are contained in the shared library container, wherein at least some of the executable application code contained in the set of application containers reference one or more of the libraries contained in the shared library container;

determining severity values of known vulnerabilities associated with each of the libraries in the shared library container;

for each library in the shared library container, determining a percentage of the applications that use the library and a frequency with which the applications use the library; and

replacing one of the libraries in the shared library container to correct a vulnerability identified in the one of the libraries, without modifying the application code in any of the application containers.

2. The non-transitory tangible computer readable storage medium of claim 1 , further comprising scanning the set of application containers to identify which application containers contain applications that reference a particular library in the shared library container.

3. The non-transitory tangible computer readable storage medium of claim 2 , further comprising determining a number of times the particular library is referenced by all of the applications contained in all of the application containers.

4. The non-transitory tangible computer readable storage medium of claim 2 , further comprising determining a severity of a vulnerability associated with the particular library, and determining a priority value for correction of the vulnerability based on the severity of the vulnerability and the number of times the particular library is referenced by all of the applications contained in all of the application containers.

5. The non-transitory tangible computer readable storage medium of claim 4 , wherein the priority value is based on a percentage of the applications that reference the particular library.

6. The non-transitory tangible computer readable storage medium of claim 1 , further comprising assigning library prioritization values to each of the libraries using a weighted prioritization process, the weighted prioritization process assigning a library prioritization value to each particular library based on a first weight value times the severity values of the known vulnerabilities of that particular library, a second weight value times the percentage of applications that use that particular library, and a third weight value times the frequency with which the applications use that particular library.

7. The non-transitory tangible computer readable storage medium of claim 1 , further comprising generating a vulnerability report, for each library in the shared library container, identifying a set of applications that use the library and a frequency with which the applications use the library.

8. The non-transitory tangible computer readable storage medium of claim 7 , wherein the applications are implemented using microservices, and wherein the frequency with which a particular application uses the library is based on how many microservices of the particular application use the library.

9. The non-transitory tangible computer readable storage medium of claim 1 , wherein the libraries are open-source libraries.

10. The non-transitory tangible computer readable storage medium of claim 1 , further comprising adding a new library to the shared library container.

11. The non-transitory tangible computer readable storage medium of claim 1 , wherein at least two of the applications in separate application containers share access to a particular library in the shared library container by referencing the particular library in the shared library container.

12. A storage system, comprising:

a processor;

a set of storage resources including a memory;

an operating system;

a shared library container created by a containerization process, the shared library container containing a set of libraries but not executable application code;

a set of application containers created by the containerization process, wherein each application container is an independent container, separate from the shared library container, and contains one or more applications implemented as executable application code for execution on the operating system of the storage system and configuration files, but not any library of the set of libraries that are contained in the shared library container, wherein at least some of the application code contained in the set of application containers reference one or more of the libraries contained in the shared library container;

a vulnerability management system containing first control logic configured to determine severity values of known library-based vulnerabilities associated with each of the libraries in the shared library container, and for each library, determine a percentage of the applications that use the library and a frequency with which the applications use the library; and

a vulnerability prioritization system configured to select and replace one of the libraries in the shared library container to correct a vulnerability identified in the one of the libraries, without modifying the application code in any of the application containers.

13. The storage system of claim 12 , wherein at least some of the applications are implemented using microservices.

14. The storage system of claim 13 , wherein one of the microservices is a library access microservice configured to execute library calls on the shared library container.

15. The storage system of claim 12 , wherein the vulnerability prioritization system containing second control logic configured to assign a respective library prioritization value to each of the libraries using a weighted prioritization process, the weighted prioritization process configured to assign a library prioritization value to each particular library based on a first weight value times the severity values of the known vulnerabilities of that particular library, a second weight value times the percentage of applications that use that particular library, and a third weight value times the frequency with which the applications use that particular library.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2021
From: JANAKIRAMAN, TAMILARASAN; SUBBARAMAN, KANNAN; VAJRAVEL, VIJAYASARATHY
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 055806/0799 →