IP Library Granted Patent US 11,966,462
Granted Patent B2
US 11,966,462 · App. 17/449,327 · Granted Apr 23, 2024

Malicious dependency prevention

Inventor: Aleksandr Krasnov (Richmond, KY)
Assignee: Dropbox, Inc.
G06F21/53G06F9/455H04L9/3236H04L63/166G06F2221/033G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,966,462
App. No.
17/449,327
Granted
Apr 23, 2024
Kind
B2
Abstract

A computing system identifies a third-party dependency to be added to a codebase. The third-party dependency is hosted on a third-party server. The computing system downloads the third-party dependency within a secure runtime environment. The computing system generates a signature value for the third-party dependency. The computing system compares the signature value to a database of signature values of approved third-party dependencies. Upon determining that the signature value does not correspond to any signature values of the approved third-party dependencies, the computing system executes the third-party dependency within the secure runtime environment. The computing system monitors the execution of the third-party dependency within the secure runtime environment to identify suspicious activity. Upon determining that the third-party dependency is not exhibiting suspicious activity, the computing system adds the signature value to the database of signature values of approved third-party dependencies.

Claims (74)

1. A method comprising:

identifying, by a computing system, a third-party dependency to be added to a codebase, the third-party dependency hosted on a third-party server;

downloading, by the computing system, the third-party dependency within a secure runtime environment;

generating, by the computing system, a signature value for the third-party dependency;

comparing, by the computing system, the signature value to a database of signature values of approved third-party dependencies;

upon determining, by the computing system, that the signature value does not correspond to any signature values of the approved third-party dependencies, executing the third-party dependency with a replica of the codebase within the secure runtime environment;

monitoring, by the computing system, the execution of the third-party dependency within the secure runtime environment to identify whether the third-party dependency violates a security rule;

upon determining, by the computing system, that the third-party dependency does not violate the security rule, adding the signature value to the database of signature values of approved third-party dependencies; and

after the third-party dependency has been determined not to exhibit suspicious activity and has been imported into the codebase:

executing, by the computing system, a service incorporating the third-party dependency on a runtime server, and

monitoring, by the computing system, behavior of the third-party dependency as incorporated in the service on the runtime server.

2. The method of claim 1 , wherein monitoring, by the computing system, the behavior of the third-party dependency as incorporated in the service comprises:

utilizing a machine learning model to analyze the behavior of the third-party dependency.

3. The method of claim 1 , further comprising:

allowing a developer to utilize the third-party dependency in the codebase by pulling the third-party dependency from the database of approved third-party dependencies.

4. The method of claim 1 , wherein identifying, by the computing system, the third-party dependency to be added to the codebase comprises:

receiving a uniform resource locator (URL) from a developer device, wherein the uniform resource locator identifies a location of the third-party dependency on a third-party server.

5. The method of claim 4 , wherein downloading, by the computing system, the third-party dependency within the secure runtime environment comprises:

generating a hypertext transfer protocol (HTTP) request to the third-party server based on the URL.

6. The method of claim 1 , wherein monitoring, by the computing system, the execution of the third-party dependency within the secure runtime environment to identify suspicious activity comprises:

monitoring behavior of the third-party dependency to identify any anomalies or malicious calls outside of an expected perimeter.

7. The method of claim 1 , further comprising:

executing, by the computing system, the codebase in a second secure runtime environment.

8. The method of claim 7 , wherein monitoring, by the computing system, the execution of the third-party dependency within the secure runtime environment to identify whether the third-party dependency violates the security rule comprises:

identifying a first set of metadata generated by the secure runtime environment, wherein the first set of metadata comprises a first set of calls made during execution of the third-party dependency with the replica of the codebase;

identifying a second set of metadata generated by the second secure runtime environment, wherein the second set of metadata comprises a second set of calls made during execution of the codebase without the third-party dependency; and

comparing the first set of metadata to the second set of metadata to determine whether the third-party dependency triggered a call that violates the security rule.

9. A method comprising:

identifying, by a computing system, a virtualization element for use with a codebase;

downloading, by the computing system, a virtualization image corresponding to the virtualization element within a secure runtime environment;

hashing, by the computing system, the virtualization image to generate a hash value for the virtualization image;

comparing, by the computing system, the hash value to a database of approved virtualization images;

upon determining, by the computing system, that the hash value does not correspond to any of the approved virtualization images, provisioning the virtualization element within the secure runtime environment using the virtualization image;

monitoring, by the computing system, behavior of the virtualization element within the secure runtime environment to identify suspicious activity;

upon determining, by the computing system, that the virtualization element is not exhibiting suspicious activity, allowing a developer to utilize the virtualization image with the codebase;

identifying, by the computing system, an updated virtualization image to be added to the codebase, the updated virtualization image corresponding to a new version of the virtualization image;

downloading, by the computing system, the updated virtualization image within the secure runtime environment;

generating, by the computing system, a second signature value for the updated virtualization image;

comparing, by the computing system, the second signature value to the database of signature values of approved virtualization images; and

upon determining, by the computing system, that the second signature value does not correspond to at least one signature value of the approved virtualization images, provisioning a second virtualization element using the updated virtualization image within the secure runtime environment.

10. The method of claim 9 , wherein allowing the developer to utilize the virtualization image in the codebase comprises:

pulling the virtualization image from the database of approved virtualization images.

11. The method of claim 9 , wherein identifying, by the computing system, the virtualization element to be added to the codebase comprises:

receiving the virtualization element from a developer device via a security server portal executing thereon.

12. The method of claim 9 , monitoring, by the computing system, the behavior of the virtualization element within the secure runtime environment to identify suspicious activity comprises:

monitoring the behavior of the virtualization element to identify any anomalies or malicious calls outside of an expected perimeter.

13. The method of claim 9 , further comprising:

identifying, by the computing system, a second virtualization image to be added to the codebase;

downloading, by the computing system, the second virtualization image within the secure runtime environment;

generating, by the computing system, a second signature value for the second virtualization image;

comparing, by the computing system, the second signature value to the database of signature values of approved virtualization images; and

upon determining, by the computing system, that the second signature value corresponds to at least one signature value of the approved virtualization images, alerting a developer that the second virtualization image is not malicious.

14. A method comprising:

identifying, by a computing system, a third-party dependency to be added to a codebase, the third-party dependency hosted on a third-party server, the identifying comprising receiving a uniform resource locator (URL) from a developer device, wherein the uniform resource locator identifies a location of the third-party dependency on a third-party server;

downloading, by the computing system, the third-party dependency within a secure runtime environment;

generating, by the computing system, a signature value for the third-party dependency;

comparing, by the computing system, the signature value to a database of signature values of approved third-party dependencies;

upon determining, by the computing system, that the signature value does not correspond to any signature values of the approved third-party dependencies, executing the third-party dependency with a replica of the codebase within the secure runtime environment;

monitoring, by the computing system, the execution of the third-party dependency within the secure runtime environment to identify whether the third-party dependency violates a security rule; and

upon determining, by the computing system, that the third-party dependency does not violate the security rule, adding the signature value to the database of signature values of approved third-party dependencies.

15. The method of claim 14 , wherein downloading, by the computing system, the third-party dependency within the secure runtime environment comprises:

generating a hypertext transfer protocol (HTTP) request to the third-party server based on the URL.

16. A method comprising:

identifying, by a computing system, a third-party dependency to be added to a codebase, the third-party dependency hosted on a third-party server;

downloading, by the computing system, the third-party dependency within a secure runtime environment;

generating, by the computing system, a signature value for the third-party dependency;

comparing, by the computing system, the signature value to a database of signature values of approved third-party dependencies;

upon determining, by the computing system, that the signature value does not correspond to any signature values of the approved third-party dependencies, executing the third-party dependency with a replica of the codebase within the secure runtime environment;

executing, by the computing system, the codebase in a second secure runtime environment;

monitoring, by the computing system, the execution of the third-party dependency within the secure runtime environment to identify whether the third-party dependency violates a security rule, the monitoring comprising:

identifying a first set of metadata generated by the secure runtime environment, wherein the first set of metadata comprises a first set of calls made during execution of the third-party dependency with the replica of the codebase;

identifying a second set of metadata generated by the second secure runtime environment, wherein the second set of metadata comprises a second set of calls made during execution of the codebase without the third-party dependency, and

comparing the first set of metadata to the second set of metadata to determine whether the third-party dependency triggered a call that violates the security rule; and

upon determining, by the computing system, that the third-party dependency does not violate the security rule, adding the signature value to the database of signature values of approved third-party dependencies.

Assignments (2)
SECURITY INTEREST Recorded Dec 12, 2024
From: DROPBOX, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069604/0611 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2021
From: KRASNOV, ALEKSANDR
To: DROPBOX, INC.
Reel/Frame 057641/0096 →
Continuity (1)
Related Publication 20230094735A1 · Mar 30, 2023
Cited By (1)
US 12,487,801