IP Library › Granted Patent US 12,481,794
Granted Patent B2
US 12,481,794 · App. 18/185,276 · Granted Nov 25, 2025

Analyzing scripts to create and enforce security policies in dynamic development pipelines

Inventors: Michael Balber (Be'erot Yitzhak, IL); Eli Shemesh (Or Yehuda, IL)
Assignee: CyberArk Software Ltd.
G06F21/64G06F8/427
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,481,794
App. No.
18/185,276
Filed
Mar 16, 2023
Granted
Nov 25, 2025
Kind
B2
Art Unit
2438
USPC
726/1
Abstract

Disclosed embodiments relate to systems and methods for enforcing security policies in dynamic development pipelines. Techniques include accessing a build script, including a set of instructions for a software build process, parsing the build script to identify a set of scripted build instructions, determining a set of expected build actions based on the scripted build instructions, and constructing a representation of the set of expected build actions. The techniques may further include automatically generating a tiered security policy based on the representation of the set of expected build actions, monitoring a dynamic pipeline running the build script, and enforcing the security policy for the dynamic pipeline environment.

Claims (43)

1 . A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for enforcing security policies in dynamic development pipelines, the operations comprising:

accessing a build script including a set of instructions for a software build process;

parsing the build script to identify a set of scripted build instructions;

determining a set of expected build actions based on the set of scripted build instructions;

constructing a representation of the set of expected build actions;

automatically generating a tiered security policy based on the representation of the set of expected build actions;

monitoring a dynamic development pipeline environment running the build script; and

enforcing the security policy for the dynamic development pipeline environment.

2 . The non-transitory computer readable medium of claim 1 , wherein monitoring the dynamic development pipeline environment further includes the use of additional software components preinstalled on the dynamic development pipeline environment.

3 . The non-transitory computer readable medium of claim 1 , wherein monitoring the dynamic development pipeline environment further includes collecting automated messages, commands, and API calls.

4 . The non-transitory computer readable medium of claim 3 , wherein the automated messages include HTTP messages sent to a predefined URL.

5 . The non-transitory computer readable medium of claim 3 , wherein collecting automated messages, commands and API calls includes collecting Command Line Interface (CLI) commands.

6 . The non-transitory computer readable medium of claim 2 , wherein monitoring the dynamic development pipeline environment includes collecting information associated with one or more build events.

7 . The non-transitory computer readable medium of claim 2 , wherein at least one of the additional software components is a ptrace tracing tool.

8 . The non-transitory computer readable medium of claim 2 , wherein at least one of the additional software components is an extended Berkeley Packet Filter (eBPF) tracing tool.

9 . The non-transitory computer readable medium of claim 1 , wherein monitoring the dynamic development pipeline environment includes tracking network traffic between a build machine and a source code manager or a repository.

10 . The non-transitory computer readable medium of claim 1 , wherein enforcing the security policy includes terminating a build process running on a build machine.

11 . The non-transitory computer readable medium of claim 1 , wherein enforcing the security policy includes blocking deployment of source code from a repository to a build machine.

12 . The non-transitory computer readable medium of claim 1 , wherein enforcing the security policy includes blocking deployment of an artifact to a production environment.

13 . The non-transitory computer readable medium of claim 1 , wherein enforcing the security policy includes interfering with at least one event within the dynamic development pipeline environment.

14 . The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:

determining a set of expected sub-actions based on the build actions; and wherein:

the representation includes the set of expected build actions and sub-actions; and

the tiered security policy is based on the representation of the set of expected build actions and sub-actions.

15 . The non-transitory computer readable medium of claim 1 , wherein constructing the representation of the set of expected build actions includes identifying specific command executions contained in the set of scripted build instructions.

16 . The non-transitory computer readable medium of claim 1 , wherein:

the set of scripted build instructions include accessing an external file; and

the set of expected build actions include connecting to a repository containing the external file.

17 . The non-transitory computer readable medium of claim 1 , wherein:

the set of scripted build instructions includes building, tagging, and pushing an image to a container registry;

the set of expected build actions includes connecting to the container registry; and

the operations further comprise generating a set of system call commands.

18 . The non-transitory computer readable medium of claim 1 , wherein the tiered security policy is based on dependencies between expected build actions.

19 . A computer-implemented method for enforcing security policies in dynamic development pipelines, comprising:

accessing a build script including a set of instructions for a software build process;

parsing the build script to identify a set of scripted build instructions;

determining a set of expected build actions based on the set of scripted build instructions;

constructing a representation of the set of expected build actions;

automatically generating a tiered security policy based on the representation of the set of expected build actions;

monitoring a dynamic development pipeline environment running the build script; and

enforcing the security policy for the dynamic development pipeline environment.

20 . The computer implemented method of claim 19 , wherein monitoring the dynamic development pipeline environment includes collecting information associated with one or more build events using software components preinstalled on the dynamic development pipeline environment; and

wherein monitoring the dynamic development pipeline environment further includes receiving automated HTTP messages sent to a predefined URL.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: SHEMESH, ELI; BALBER, MICHAEL
To: CYBERARK SOFTWARE LTD.
Reel/Frame 063007/0545 →
Continuity (2)
Continuation In Part 17741533 · May 11, 2022
Related Publication 20230367911A1 · Nov 16, 2023
References Cited (26)
US 10261782B2 · Suarez · 2019 [cited by applicant]
US 11093377B2 · Burrell · 2021 [cited by applicant]
US 11144438B1 · Teixeira · 2021 [cited by applicant]
US 11265292B1 · Leviseur · 2022 [cited by applicant]
US 11495347B2 · De Armas · 2022 [cited by examiner]
US 11947946B1 · Rao · 2024 [cited by examiner]
US 20160253625A1 · Casey · 2016 [cited by applicant]
US 20170116412A1 · Stopel · 2017 [cited by applicant]
US 20180121659A1 · Sawhney · 2018 [cited by applicant]
US 20180300480A1 · Sawhney · 2018 [cited by applicant]
US 20180321918A1 · Mcclory · 2018 [cited by applicant]
US 20190180036A1 · Shukla · 2019 [cited by applicant]
US 20200082094A1 · Mcallister · 2020 [cited by applicant]
US 20200082095A1 · Mcallister · 2020 [cited by applicant]
US 20200097357A1 · Shwartz · 2020 [cited by applicant]
US 20200097662A1 · Hufsmith · 2020 [cited by applicant]
US 20200202006A1 · Shah · 2020 [cited by applicant]
US 20210026969A1 · Hod · 2021 [cited by applicant]
US 20210157623A1 · Chandrashekar · 2021 [cited by applicant]
US 20210382813A1 · Moondhra · 2021 [cited by applicant]
US 20220091830A1 · Ionescu · 2022 [cited by applicant]
US 20220138004A1 · Nandakumar · 2022 [cited by applicant]
US 20220215101A1 · Rioux · 2022 [cited by applicant]
US 20230376603A1 · Yaron · 2023 [cited by examiner]
WO WO2020252088A1 · 2020 [cited by applicant]
Alex Ilgayev, How We Discovered Vulnerabilities in CI/CD Pipelines of Popular Open-Source Projects, Mar. 18, 2022, (Mar. 18, 2022), pp. 1-17, XP093084578, Retrieved from the Internet: URL:https://cycode.com/blog/github-… [cited by applicant]