IP Library Granted Patent US 12,169,714
Granted Patent B2
US 12,169,714 · App. 17/804,067 · Granted Dec 17, 2024

Techniques for code isolation in static analysis of applications using application framework

Inventors: Amir Sidis (Tel Aviv, IL); Saar Mano (Givatayim, IL); Eyal Mamo (Tel Aviv, IL)
Assignee: Bionic Stork Ltd.
G06F8/75G06F11/3414G06F11/3457G06F9/45504
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,169,714
App. No.
17/804,067
Granted
Dec 17, 2024
Kind
B2
Abstract

A system and method for performing static analysis on an application having an external initialization includes receiving an application code having an external initialization code component, the application code deployed in a cloud computing environment; simulating a local computing environment in which to execute the received application code; emulating at least the external initialization code component in the simulated local computing environment; recording an action performed by the external initialization code component; and generating a set of instructions for a static analyzer to perform static analysis on the application and the generated set of instructions.

Claims (44)

1. A method comprising:

receiving an application code comprising an external initialization code component, the application code deployed in a cloud computing environment;

simulating a local computing environment in which to execute the application code;

emulating the external initialization code component in the simulated local computing environment;

recording, by a processing circuitry, an action by the external initialization code component to the application code during code initialization; and

generating, based on the action, a set of instructions for a static analyzer to perform static analysis on the application code using the set of instructions.

2. The method of claim 1 , wherein the code initialization is an inversion of control framework.

3. The method of claim 1 , further comprising:

deploying a virtual workload in an asset monitoring environment, the virtual workload simulating the local computing environment.

4. The method of claim 1 , wherein the application code is received from a collector deployed, by an asset monitoring system, for a predefined duration on a workload executing in the cloud computing environment.

5. The method of claim 1 , further comprising:

emulating a response to a call in the external initialization code component.

6. The method of claim 5 , further comprising:

emulating another response to the call, in response to determining that a prior emulated response resulted in the application code failing to initialize.

7. The method of claim 1 , wherein the set of instructions comprises at least one of machine code, bytecode, source code, or interpreted script language.

8. The method of claim 1 , wherein the local computing environment is an isolated environment.

9. A non-transitory computer readable medium storing instructions that, when executed by a processing circuitry, cause the processing circuitry to:

receive an application code comprising an external initialization code component, the application code deployed in a cloud computing environment;

simulate a local computing environment in which to execute the application code;

emulate the external initialization code component in the simulated local computing environment;

record, by the processing circuitry, an action by the external initialization code component to the application code during code initialization; and

generate, based on the action, a set of instructions for a static analyzer to perform static analysis on the application code using the set of instructions.

10. The non-transitory computer readable medium of claim 9 , wherein the application code is received from a collector deployed, by an asset monitoring system, for a predefined duration on a workload executing in the cloud computing environment.

11. The non-transitory computer readable medium of claim 9 , wherein the processing circuitry is further to:

emulate a response to a call in the external initialization code component.

12. The non-transitory computer readable medium of claim 9 , wherein the local computing environment is an isolated environment.

13. A system comprising:

a processing circuitry; and

a memory operatively coupled to the processing circuitry, the memory containing instructions that, when executed by the processing circuitry, cause the system to:

receive an application code comprising an external initialization code component, the application code deployed in a cloud computing environment;

simulate a local computing environment in which to execute the application code;

emulate the external initialization code component in the simulated local computing environment;

record an action by the external initialization code component to the application code during code initialization; and

generate, based on the action, a set of instructions for a static analyzer to perform static analysis on the application code using the set of instructions.

14. The system of claim 13 , wherein the code initialization is an inversion of control framework.

15. The system of claim 13 , wherein the memory contains further instructions that, when executed by the processing circuitry, further cause the system to:

deploy a virtual workload in an asset monitoring environment, the virtual workload simulating the local computing environment.

16. The system of claim 13 , wherein the application code is received from a collector deployed, by an asset monitoring system, for a predefined duration on a workload executing in the cloud computing environment.

17. The system of claim 13 , wherein the memory contains further instructions that, when executed by the processing circuitry, further cause the system to:

emulate a response to a call in the external initialization code component.

18. The system of claim 17 , wherein the memory contains further instructions that, when executed by the processing circuitry, further cause the system to:

emulate another response to the call, in response to determining that a prior emulated response resulted in the application code failing to initialize.

19. The system of claim 13 , wherein the set of instructions comprises at least one of machine code, bytecode, source code, or interpreted script language.

20. The system of claim 13 , wherein the local computing environment is an isolated environment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2025
From: BIONIC STORK LTD.
To: CROWDSTRIKE, INC.
Reel/Frame 070147/0938 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2022
From: SIDIS, AMIR; MANO, SAAR; MAMO, EYAL
To: BIONIC STORK LTD.
Reel/Frame 060019/0247 →
Continuity (1)
Related Publication 20230385057A1 · Nov 30, 2023