IP Library › Granted Patent US 12,536,288
Granted Patent B2
US 12,536,288 · App. 17/736,417 · Granted Jan 27, 2026

Detecting backdoors in binary software code

Inventors: Neil David Jonathan Duggan (Basingstoke, GB); Vincenzo Kazimierz Marcovecchio (Toronto, CA); Adam John Boulton (Wirral, GB)
Assignee: BlackBerry Limited
G06F21/57G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,288
App. No.
17/736,417
Granted
Jan 27, 2026
Kind
B2
Abstract

Systems, methods, and software can be used to detect backdoors in binary software code. In some aspects, a method comprises: obtaining, by a server, binary software code corresponding to source code; generating, by the server, a backdoor abstraction of the binary software code; and generating, by the server, a backdoor risk assessment based on the backdoor abstraction of the binary software code.

Claims (68)

1 . A method, comprising:

obtaining, by a server, binary software code corresponding to source code;

generating, by the server, a backdoor abstraction of the binary software code by identifying one or more library calls indicative of a potential backdoor in the binary software code; and

generating, by the server, a backdoor risk assessment based on the backdoor abstraction of the binary software code, wherein generating the backdoor risk assessment comprises:

determining, by the server, that none of the source code corresponds to the potential backdoor in the backdoor abstraction of the binary software code by parsing the source code to search for the potential backdoor; and

in response to determining that none of the source code corresponds to the potential backdoor, determining that a risk is inserted during a generation of the binary software code corresponding to the source code and including the risk in the backdoor risk assessment.

2 . The method of claim 1 , wherein generating the backdoor abstraction comprises:

including, by the server and in the backdoor abstraction of the binary software code, a potential backdoor representation corresponding to the one or more library calls.

3 . The method of claim 1 , wherein generating the backdoor abstraction comprises:

determining, by the server, that the binary software code comprises a string; and

including, by the server, a potential backdoor representation corresponding to the string in the backdoor abstraction of the binary software code.

4 . The method of claim 3 , wherein the string comprises at least one of:

a Uniform Resource Locator (URL);

a hardcoded user credential; or

a high entropy string.

5 . The method of claim 1 , wherein generating the backdoor risk assessment comprises:

comparing the backdoor abstraction of the binary software code and a backdoor abstraction of the source code.

6 . The method of claim 1 , comprising:

storing, by the server, the backdoor abstraction of the binary software code as a baseline;

obtaining, by the server, additional binary software code;

generating, by the server, an additional backdoor abstraction of the additional binary software code; and

generating, by the server, an additional backdoor risk assessment based on the baseline and the additional backdoor abstraction.

7 . A non-transitory computer-readable medium containing instructions which, when executed, cause a computing device to perform operations comprising:

obtaining, by a server, binary software code corresponding to source code;

generating, by the server, a backdoor abstraction of the binary software code by identifying one or more library calls indicative of a potential backdoor in the binary software code; and

generating, by the server, a backdoor risk assessment based on the backdoor abstraction of the binary software code, wherein generating the backdoor risk assessment comprises:

determining, by the server, that none of the source code corresponds to the potential backdoor in the backdoor abstraction of the binary software code by parsing the source code to search for the potential backdoor; and

in response to determining that none of the source code corresponds to the potential backdoor, determining that a risk is inserted during a generation of the binary software code corresponding to the source code and including the risk in the backdoor risk assessment.

8 . The non-transitory computer-readable medium of claim 7 , wherein generating the backdoor abstraction comprises:

including, by the server and in the backdoor abstraction of the binary software code, a potential backdoor representation corresponding to the one or more library calls.

9 . The non-transitory computer-readable medium of claim 7 , wherein generating the backdoor abstraction comprises:

determining, by the server, that the binary software code comprises a string; and

including, by the server, a potential backdoor representation corresponding to the string in the backdoor abstraction of the binary software code.

10 . The non-transitory computer-readable medium of claim 9 , wherein the string comprises at least one of:

a Uniform Resource Locator (URL);

a hardcoded user credential; or

a high entropy string.

11 . The non-transitory computer-readable medium of claim 7 , wherein generating the backdoor risk assessment comprises:

comparing the backdoor abstraction of the binary software code and a backdoor abstraction of the source code.

12 . The non-transitory computer-readable medium of claim 7 , comprising:

storing, by the server, the backdoor abstraction of the binary software code as a baseline;

obtaining, by the server, additional binary software code;

generating, by the server, an additional backdoor abstraction of the additional binary software code; and

generating, by the server, an additional backdoor risk assessment based on the baseline and the additional backdoor abstraction.

13 . A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

obtaining, by a server, binary software code corresponding to source code;

generating, by the server, a backdoor abstraction of the binary software code by identifying one or more library calls indicative of a potential backdoor in the binary software code; and

generating, by the server, a backdoor risk assessment based on the backdoor abstraction of the binary software code, wherein generating the backdoor risk assessment comprises:

determining, by the server, that none of the source code corresponds to the potential backdoor in the backdoor abstraction of the binary software code by parsing the source code to search for the potential backdoor; and

in response to determining that none of the source code corresponds to the potential backdoor, determining that a risk is inserted during a generation of the binary software code corresponding to the source code and including the risk in the backdoor risk assessment.

14 . The computer-implemented system of claim 13 , wherein generating the backdoor abstraction comprises:

including, by the server and in the backdoor abstraction of the binary software code, a potential backdoor representation corresponding to the one or more library calls.

15 . The computer-implemented system of claim 13 , wherein generating the backdoor abstraction comprises:

determining, by the server, that the binary software code comprises a string; and

including, by the server, a potential backdoor representation corresponding to the string in the backdoor abstraction of the binary software code.

16 . The computer-implemented system of claim 15 , wherein the string comprises at least one of:

a Uniform Resource Locator (URL);

a hardcoded user credential; or

a high entropy string.

17 . The computer-implemented system of claim 13 , wherein generating the backdoor risk assessment comprises:

comparing the backdoor abstraction of the binary software code and a backdoor abstraction of the source code.

18 . The computer-implemented system of claim 13 , the one or more operations comprising:

storing, by the server, the backdoor abstraction of the binary software code as a baseline;

obtaining, by the server, additional binary software code;

generating, by the server, an additional backdoor abstraction of the additional binary software code; and

generating, by the server, an additional backdoor risk assessment based on the baseline and the additional backdoor abstraction.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE ASSIGNEE'S NAME PREVIOUSLY RECORDED AT REEL: 060337 FRAME: 0601. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 16, 2022
From: BOULTON, ADAM JOHN
To: BLACKBERRY UK LIMITED
Reel/Frame 061102/0357 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2022
From: BOULTON, ADAM JOHN
To: RESEARCH IN MOTION LIMITED
Reel/Frame 060337/0601 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2022
From: BLACKBERRY UK LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 060292/0760 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2022
From: DUGGAN, NEIL DAVID JONATHAN
To: BLACKBERRY UK LIMITED
Reel/Frame 059904/0444 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2022
From: MARCOVECCHIO, VINCENZO KAZIMIERZ
To: BLACKBERRY LIMITED
Reel/Frame 059904/0528 →
Continuity (1)
Related Publication 20230359739A1 · Nov 9, 2023
References Cited (23)
US 9465942B1 · Kane-Parry et al. · 2016 [cited by applicant]
US 11550903B1 · Epstein · 2023 [cited by examiner]
US 11556640B1 · Tully · 2023 [cited by examiner]
US 20120079452A1 · Nir-Buchbinder · 2012 [cited by examiner]
US 20140236919A1 · Liu · 2014 [cited by examiner]
US 20180239898A1 · Haerterich et al. · 2018 [cited by applicant]
US 20190220596A1 · Lie et al. · 2019 [cited by applicant]
US 20190227902A1 · Cheng et al. · 2019 [cited by applicant]
US 20190251251A1 · Carson · 2019 [cited by applicant]
US 20210034757A1 · Boulton · 2021 [cited by examiner]
US 20210200840A1 · Kannan · 2021 [cited by examiner]
US 20210216636A1 · Devries · 2021 [cited by examiner]
US 20220292201A1 · Sasaki et al. · 2022 [cited by applicant]
Non-Final Office Action in U.S. Appl. No. 17/736,420, mailed on Apr. 4, 2024, 41 pages. [cited by applicant]
Extended European Search Report in European Appln. No. 23164043.4, mailed on Sep. 22, 2023, 6 pages. [cited by applicant]
U.S. Appl. No. 17/736,420, Duggan et al., May 4, 2022. [cited by applicant]
Apiiro.com [online], “Detect and Prevent the SolarWinds Build-Time Code Injection Attack” Feb. 17, 2021, [retrieved on Jul. 6, 2022], retrieved from : URL <https://apiiro.com/blog/detect-and-prevent-the-solarwinds-build… [cited by applicant]
Docs.microsoft.com [online], “Tutorial: Detect suspicious user activity with UEBA” Mar. 23, 2022, [retrieved on Jul. 6, 2022], retrieved from : URL <https://docs.microsoft.com/en-us/defender-cloud-apps/tutorial-suspicio… [cited by applicant]
Klieber, “A Technique for Decompiling Binary Code for Software Assurance and Localized Repair” Carnegie Mellon University, SEI Blog, Oct. 11, 2021, 6 pages. [cited by applicant]
Miyani, “Binpro: A Tool For Binary Backdoor Accountability in Code Audits” Master Thesis, University of Toronto, Electrical and Computer Engineering, Nov. 2016, 45 pages. [cited by applicant]
Non-Final Office Action in U.S. Appl. No. 17/736,420, mailed on Dec. 4, 2024, 25 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 17/736,420, mailed on May 22, 2025, 31 pages. [cited by applicant]
Office Action in European Appln. No. 23164601.9, mailed on Apr. 15, 2025, 4 pages. [cited by applicant]