IP Library Granted Patent US 12,265,627
Granted Patent B1
US 12,265,627 · App. 17/895,879 · Granted Apr 1, 2025

Behavioral analysis for identification of malicious code

Inventors: Adrian Wood (Clemmons, NC); Douglas Brookes Tucker (Westbrook, CT); Michael Barone (Wallingford, CT)
Assignee: Wells Fargo Bank, N.A.
G06F21/577G06F21/565
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,627
App. No.
17/895,879
Granted
Apr 1, 2025
Kind
B1
Abstract

Techniques are described for a behavioral analysis of metadata associated with source code to identify malicious source code. For example, this disclosure describes a computing system configured to obtain metadata associated with source code of a software package. The computing system is also configured to determine, based on the metadata associated with source code, whether there are any anomalies associated with the source code. The computing system is further configured to, in response to determining that there is at least one anomaly associated with the source code, compute a score for the software package. The computing system is also configured to perform an action based on the score for the software package.

Claims (42)

1. A method comprising:

obtaining, by a computing system, metadata associated with source code of a software package;

determining, by the computing system and based on the metadata associated with source code, whether there are any anomalies associated with the source code;

in response to determining that there is at least one anomaly associated with the source code, computing, by the computing system, an overall risk level for the software package, wherein computing the overall risk level for the software package is based on an author risk score that specifies a value that indicates a risk level of behavior of the author, a popularity score that specifies a value that indicates the popularity of the software package, and a health score that specifies a value that indicates a health of the software package; and

performing, by the computing system, an action based on the overall risk level for the software package, wherein performing the action comprises blocking use of the software package in a software product.

2. The method of claim 1 , wherein determining whether there are any anomalies associated with the source code comprises:

determining whether there are any anomalies associated with the source code based on behavior of an author of the source code.

3. The method of claim 2 , wherein determining whether there are any anomalies associated with the source code based on behavior of an author of the source code comprises:

determining whether there are any anomalies associated with one or more actions performed by the author of the source code associated with a commit of the source code.

4. The method of claim 2 , wherein determining whether there are any anomalies associated with the source code based on behavior of an author of the source code comprises:

determining whether there are any anomalies associated with the source code based on a time a commit of the source code occurred.

5. The method of claim 2 , wherein determining whether there are any anomalies associated with the source code based on behavior of an author of the source code comprises:

determining whether the author of the source code committed one or more lines of source code for a plurality of software packages.

6. The method of claim 2 , wherein determining whether there are any anomalies associated with the source code based on behavior of an author of the source code comprises:

determining whether a commit of the source code was unsigned from the author who typically signs.

7. The method of claim 1 , wherein performing the action comprises outputting, by the computing system and to an administrator computing device, an indication that the software package has at least one anomaly associated with the source code.

8. The method of claim 1 , wherein obtaining metadata associated with source code of the software package comprises:

obtaining metadata associated with source code from one or more of a source code repository or software package manager.

9. A computing system comprising:

a memory; and

one or more processors in communication with the memory, the one or more processors configured to:

obtain metadata associated with source code of a software package;

determine, based on the metadata associated with source code, whether there are any anomalies associated with the source code;

in response to determining that there is at least one anomaly associated with the source code, compute an overall risk level for the software package, wherein computing the overall risk level for the software package is based on an author risk score that specifies a value that indicates a risk level of behavior of the author, a popularity score that specifies a value that indicates the popularity of the software package, and a health score that specifies a value that indicates a health of the software package; and

perform an action based on the overall risk level for the software package, wherein performing the action comprises blocking use of the software package in a software product.

10. The computing system of claim 9 , wherein to determine whether there are any anomalies associated with the source code, the one or more processors are configured to:

determine whether there are any anomalies associated with the source code based on behavior of an author of the source code.

11. The computing system of claim 10 , wherein to determine whether there are any anomalies associated with the source code based on behavior of an author of the source code, the one or more processors are configured to:

determine whether there are any anomalies associated with one or more actions performed by the author of the source code associated with a commit of the source code.

12. The computing system of claim 10 , wherein to determine whether there are any anomalies associated with the source code based on behavior of an author of the source code, the one or more processors are configured to:

determine whether there are any anomalies associated with the source code based on a time a commit of the source code occurred.

13. The computing system of claim 10 , wherein to determine whether there are any anomalies associated with the source code based on behavior of an author of the source code, the one or more processors are further configured to:

determine whether the author of the source code committed one or more lines of source code for a plurality of software packages.

14. The computing system of claim 10 , wherein to determine whether there are any anomalies associated with the source code based on behavior of an author of the source code, the one or more processors are further configured to:

determine whether a commit of the source code was unsigned from the author who typically signs.

15. The computing system of claim 9 , wherein to perform the action, the one or more processors are configured to:

output, to an administrator computing device, an indication that the software package has at least one anomaly associated with the source code.

16. Non-transitory computer-readable storage media comprising instructions that, when executed, cause one or more processors to:

obtain metadata associated with source code of a software package;

determine, based on the metadata associated with source code, whether there are any anomalies associated with the source code;

in response to determining that there is at least one anomaly associated with the source code, compute an overall risk level for the software package, wherein computing the overall risk level for the software package is based on an author risk score that specifies a value that indicates a risk level of behavior of the author, a popularity score that specifies a value that indicates the popularity of the software package, and a health score that specifies a value that indicates a health of the software package; and

perform an action based on the overall risk level for the software package, wherein performing the action comprises blocking use of the software package in a software product.

Assignments (2)
REQUEST FOR ADDRESS CHANGE Recorded Dec 5, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 073895/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2022
From: WOOD, ADRIAN; TUCKER, DOUGLAS BROOKES; BARONE, MICHAEL
To: WELLS FARGO BANK, N.A.
Reel/Frame 061276/0936 →
References Cited (25)
US 8499063B1 · Satish · 2013 [cited by examiner]
US 10817604B1 · Kimball · 2020 [cited by examiner]
US 11263317B2 · Kandel et al. · 2022 [cited by applicant]
US 11487538B1 · Gove, Jr. · 2022 [cited by examiner]
US 20120137138A1 · Gregorovic · 2012 [cited by examiner]
US 20150026810A1 · Friedrichs · 2015 [cited by examiner]
US 20150302198A1 · Payne · 2015 [cited by examiner]
US 20160292066A1 · Stevens · 2016 [cited by examiner]
US 20180239898A1 · Haerterich · 2018 [cited by examiner]
US 20200218806A1 · Cho · 2020 [cited by applicant]
US 20210200840A1 · Kannan · 2021 [cited by examiner]
US 20210263728A1 · Farrier · 2021 [cited by examiner]
US 20210287231A1 · Miltonberger · 2021 [cited by applicant]
US 20210385245A1 · Melson et al. · 2021 [cited by applicant]
US 20220004624A1 · Revivo et al. · 2022 [cited by applicant]
US 20220083450A1 · Geddes et al. · 2022 [cited by applicant]
US 20220308862A1 · Espinha · 2022 [cited by examiner]
US 20230019837A1 · Jennings · 2023 [cited by examiner]
CN 113656800A · 2021 [cited by applicant]
WO 2019004671A1 · 2019 [cited by applicant]
WO 2021190138A1 · 2021 [cited by applicant]
Duan et al., “Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages”, Network and Distributed Systems Security Symposium, Feb. 4, 2020, 17 pp. [cited by applicant]
Ohm et al., “Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks”, International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, Springer, Jun. 24, 2020… [cited by applicant]
Vu et al., “Poster: Towards Using Source Code Repositories to Identify Software Supply Chain Attacks”, Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, Nov. 9, 2020, pp. 2093-2095. [cited by applicant]
Xiong et al., “A Method for Assigning Probability Distributions in Attack Simulation Languages”, Complex Systems Informatics and Modeling Quarterly (CSIMQ), vol. 151, No. 26, RTU Press, Apr. 30, 2021, pp. 55-77. [cited by applicant]
Cited By (2)
US 12,407,703 US 12,670,264