IP Library Granted Patent US 11,663,322
Granted Patent B2
US 11,663,322 · App. 17/492,005 · Granted May 30, 2023

Distributed security introspection

Inventor: Michael Cervantez (San Francisco, CA)
Assignee: Salesforce, Inc.
G06F21/53G06F21/54G06F21/554G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,663,322
App. No.
17/492,005
Granted
May 30, 2023
Kind
B2
Abstract

Computer programming code may be executed via look ahead execution in a virtual machine. The computer programming code may include a first instruction to retrieve data stored in an on-demand computing services environment and a second instruction to transmit the data to a recipient. The first instruction, the second instruction, and the data may be evaluated to determine whether the execution of the computer programming code constitutes acceptable use of the on-demand computing services environment. When it is determined that the execution of the computer programming code does not constitute acceptable use of the on-demand computing services environment, further execution of the computer programming code may be halted.

Claims (31)

1. A method comprising:

partially executing computer programming code on a computing device that includes a processor and memory, the computer programming code including first, second, and third instructions;

after executing the first instruction, determining whether the second instruction or the third instruction is scheduled for execution by applying function tracing to predict code execution branching based at least in part on an action performed by the first instruction;

when it is determined that the second instruction is scheduled for execution, evaluating the first and second instructions and the action performed by the first instruction via a processor to determine whether the execution of the computer programming code constitutes malicious activity, wherein evaluating the first and second instructions comprises receiving a response message from a scoring engine implemented as a service within an on-demand computing services environment, the response message indicating whether the execution of the computer programming code constitutes malicious activity; and

after determining that the execution of the computer programming code constitutes malicious activity, halting further execution of the computer programming code.

2. The method recited in claim 1 , wherein evaluating the first and second instructions comprises transmitting a request message to the scoring engine via a network.

3. The method recited in claim 2 , wherein the request message includes the first instruction, the second instruction, and information characterizing data retrieved by the first instruction.

4. The method recited in claim 3 , wherein the data is retrieved from a multi-tenant database accessible via the on-demand computing services environment.

5. The method recited in claim 1 , wherein evaluating the first and second instructions comprises making a comparison with operations performed by a different version of the computer programming code.

6. The method recited in claim 1 , wherein evaluating the first and second instructions comprises making a comparison with operations performed by a plurality of applications known to the scoring engine.

7. The method recited in claim 1 , wherein the computer programming code is executed in a virtual machine instantiated at the request of a client organization accessing the on-demand computing services environment, and wherein the computer programming code is included in an application instantiated at the request of the client organization.

8. The method recited in claim 7 , wherein the application is authored by the client organization.

9. The method recited in claim 7 , wherein the application is authored by a third-party software developer.

10. The method recited in claim 9 , wherein the application is accessed via an application exchange that provides applications for purchase and use in the on-demand computing environment.

11. The method recited in claim 1 , wherein the service is distributed across a plurality of devices including the computing device.

12. A system comprising:

a processor configured to partially execute computer programming code on a computing device, the computer programming code including first, second, and third instructions,

wherein the processor is further configured to determine after executing the first instruction whether the second instruction or the third instruction is scheduled for execution by applying function tracing to predict code execution branching based at least in part on an action performed by the first instruction, wherein the processor is further configured to evaluate the first and second instructions and the action performed by the first instruction when it is determined that the second instruction is scheduled for execution to determine whether the execution of the computer programming code constitutes malicious activity; and

a communication interface operable to receive a response message from a scoring engine implemented as a service within an on-demand computing services environment, the response message indicating whether the execution of the computer programming code constitutes malicious activity, wherein the processor is further configured to halt further execution of the computer programming code after receiving an indication that the execution of the computer programming code constitutes malicious activity.

13. The system recited in claim 12 , wherein evaluating the first and second instructions comprises transmitting a request message to the scoring engine via a network, and wherein the request message includes the first instruction, the second instruction, and information characterizing data retrieved by the first instruction.

14. The system recited in claim 13 , wherein the data is retrieved from a multi-tenant database accessible via the on-demand computing services environment.

15. The system recited in claim 12 , wherein the computer programming code is executed in a virtual machine instantiated at the request of a client organization accessing the on-demand computing services environment, and wherein the computer programming code is included in an application instantiated at the request of the client organization.

16. The one or more non-transitory computer readable media recited in claim 12 , wherein the scoring engine is implemented as a distributed service that includes a component implemented on the computing device.

17. One or more non-transitory computer readable media having instructions stored thereon for causing a computing device to perform a method, the method comprising:

partially executing computer programming code on a computing device that includes a processor and memory, the computer programming code including first, second, and third instructions;

after executing the first instruction, determining whether the second instruction or the third instruction is scheduled for execution by applying function tracing to predict code execution branching based at least in part on an action performed by the first instruction;

when it is determined that the second instruction is scheduled for execution, evaluating the first and second instructions and the action performed by the first instruction via a processor to determine whether the execution of the computer programming code constitutes malicious activity, wherein evaluating the first and second instructions comprises receiving a response message from a scoring engine implemented as a service within an on-demand computing services environment, the response message indicating whether the execution of the computer programming code constitutes malicious activity; and

after determining that the execution of the computer programming code constitutes malicious activity, halting further execution of the computer programming code.

18. The one or more non-transitory computer readable media recited in claim 17 , wherein evaluating the first and second instructions comprises transmitting a request message to the scoring engine via a network, wherein the request message includes the first instruction, the second instruction, and information characterizing data retrieved by the first instruction, wherein the data is retrieved from a multi-tenant database accessible via the on- demand computing services environment.

19. The one or more non-transitory computer readable media recited in claim 17 , wherein the computer programming code is executed in a virtual machine instantiated at the request of a client organization accessing the on-demand computing services environment, and wherein the computer programming code is included in an application instantiated at the request of the client organization.

20. The one or more non-transitory computer readable media recited in claim 17 , wherein the scoring engine is implemented as a distributed service that includes a component implemented on the computing device.

Assignments (2)
CHANGE OF NAME Recorded Apr 14, 2023
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 063348/0981 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2021
From: CERVANTEZ, MICHAEL
To: SALESFORCE.COM, INC.
Reel/Frame 057670/0312 →
Continuity (2)
Continuation 16193816 · Nov 16, 2018
Related Publication 20220035907A1 · Feb 3, 2022