IP Library › Granted Patent US 12,748,844
Granted Patent B2
US 12,748,844 · App. 18/191,455 · Granted Sep 29, 2026

Source code vulnerability detection using deep learning

Inventor: Monika Sahu (Gurgaon, IN)
Assignee: Optum, Inc.
G06F21/563G06F21/577G06F2221/033G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,748,844
App. No.
18/191,455
Granted
Sep 29, 2026
Kind
B2
Abstract

Various embodiments of the present disclosure provide methods, apparatus, systems, computing devices, computing entities, and/or the like for detecting and locating vulnerabilities in source code. The method comprises receiving one or more source code files, matching source code from the one or more source code files to one or more program slices by parsing the source code and mapping one or more portions of the source code to the one or more program slices, wherein each of the one or more program slices comprises one or more program statements associated with one or more vulnerabilities, and generating, using a predictive machine learning model, a vulnerability prediction for each of the one or more source code files, the vulnerability prediction comprising one or more locations of vulnerable code in the source code based on the matching and a vulnerability class associated with each location of vulnerable code.

Claims (62)

1 . A computer-implemented method comprising:

receiving, by one or more processors, a source code file;

matching, by the one or more processors, source code from the source code file to a plurality of program slices by parsing the source code and mapping a portion of the source code to a program slice of the plurality of program slices, wherein the program slice comprises a program statement associated with a vulnerability;

generating, by the one or more processors and using a predictive machine learning model, a vulnerability prediction for the source code file, the vulnerability prediction comprising: (a) a location of vulnerable code in the source code based on the matching, and (b) a vulnerability class, of a plurality of vulnerability classes, associated with the vulnerable code in the source code, wherein: (i) the vulnerability prediction indicates whether the source code file increases a susceptibility to a malicious attack, (ii) the predictive machine learning model comprises a multiclass classification machine learning model and is trained based on a training dataset, and (iii) the training dataset is generated by:

(1) receiving a plurality of training source code files and the plurality of vulnerability classes associated with the plurality of training source code files,

(2) receiving a plurality of syntax features corresponding to the plurality of vulnerability classes,

(3) determining a program slicing criterion based on the plurality of syntax features,

(4) extracting a set of program slices from the plurality of training source code files based on the program slicing criterion, wherein one or more program slices of the set of program slices is extracted by performing a forward slice or a backward slice, and

(5) labeling the set of program slices with the plurality of vulnerability classes; and

initiating, by the one or more processors, one or more prediction-based actions based on the vulnerability prediction.

2 . The computer-implemented method of claim 1 , wherein:

(i) determining the program slicing criterion further comprises determining a plurality of potential vulnerability candidates by performing static analysis on a plurality of program statements associated with the plurality of training source code files and matching the plurality of program statements associated with the plurality of training source code files with the plurality of syntax features,

(ii) the program slicing criterion comprises a set of variables corresponding to a plurality of values that are required to be preserved,

(iii) the forward slice comprises a program statement affected by the program slicing criterion, and

(iv) the backward slice comprises a program statement that affects the program slicing criterion.

3 . The computer-implemented method of claim 2 , wherein the static analysis comprises generating, for a training source code file of the plurality of training source code files, at least one of: a program dependency graph, a data dependency graph, and a control dependency graph.

4 . The computer-implemented method of claim 3 , wherein the program dependency graph comprises a first set of edges representative of data dependencies between one or more program statements in the training source code file and a second set of edges representative of one or more control dependencies between the one or more program statements in the training source code file.

5 . The computer-implemented method of claim 1 , wherein the plurality of syntax features comprises application programming interface (API) or library calls, array declarations, pointer declarations, or operators in an expression.

6 . The computer-implemented method of claim 1 , wherein extracting the plurality of program slices comprises generating a source code subset, the source code subset comprising the program statement from the plurality of training source code files contributing to the vulnerability.

7 . The computer-implemented method of claim 1 , wherein the training dataset comprises the plurality of program slices assigned with labels associated with the plurality of vulnerability classes.

8 . The computer-implemented method of claim 1 , wherein the location of vulnerable code in the source code further comprises one or more of an indication of a class or a function associated with the vulnerable code or an identifier associated with a source code file comprising the source code.

9 . The computer-implemented method of claim 1 , wherein initiating the one or more prediction-based actions further comprises:

performing one or more load balancing operations to set a number of allowed computing entities used by a post-prediction system based on the vulnerability prediction.

10 . A system comprising:

one or more processors; and

at least one memory storing processor-executable instructions that, when executed by any one or more of the one or more processors, causes the one or more processors to perform operations comprising:

receive a source code file;

match source code from the source code file to a plurality of program slices by parsing the source code and mapping a portion of the source code to a program slice of the plurality of program slices, wherein the program slice comprises a program statement associated with a vulnerability;

generate, using a predictive machine learning model, a vulnerability prediction for the source code file, the vulnerability prediction comprising: (a) a location of vulnerable code in the source code based on the matching, and (b) a vulnerability class, of a plurality of vulnerability classes, associated with the vulnerable code in the source code, wherein: (i) the vulnerability prediction indicates whether the source code file increases a susceptibility to a malicious attack, (ii) the predictive machine learning model comprises a multiclass classification machine learning model and is trained based on a training dataset, and (iii) the training dataset is generated by:

(1) receiving a plurality of training source code files and the plurality of vulnerability classes associated with the plurality of training source code files,

(2) receiving a plurality of syntax features corresponding to the plurality of vulnerability classes,

(3) determining a program slicing criterion based on the plurality of syntax features,

(4) extracting a set of program slices from the plurality of training source code files based on the program slicing criterion, wherein one or more program slices of the set of program slices is extracted by performing a forward slice or a backward slice, and

(5) labeling the set of program slices with the plurality of vulnerability classes; and

initiate one or more prediction-based actions based on the vulnerability prediction.

11 . The system of claim 10 , wherein

(i) determining the program slicing criterion further comprises determining a plurality of potential vulnerability candidates by performing static analysis on a plurality of program statements associated with the plurality of training source code files and matching the plurality of program statements associated with the plurality of training source code files with the plurality of syntax features,

(ii) the program slicing criterion comprises a set of variables corresponding to a plurality of values that are required to be preserved,

(iii) the forward slice comprises a program statement affected by the program slicing criterion, and

(iv) the backward slice comprises a program statement that affects the program slicing criterion.

12 . The system of claim 11 , wherein the static analysis comprises generating, for a training source code file of the plurality of training source code files, at least one of: a program dependency graph, a data dependency graph, and a control dependency graph.

13 . The system of claim 10 , wherein the plurality of syntax features comprises application programming interface (API) or library calls, array declarations, pointer declarations, or operators in an expression.

14 . The system of claim 10 , wherein extracting the plurality of program slices comprises generating a source code subset, the source code subset comprising the program statement from the plurality of training source code files contributing to the vulnerability.

15 . The system of claim 10 , wherein the training dataset is further generated by replacing names of functions and variables in the plurality of program slices with symbolic names.

16 . One or more non-transitory computer-readable storage media including instructions that, when executed by one or more processors, cause the one or more processors to:

receive a source code file;

match source code from the source code file to a plurality of program slices by parsing the source code and mapping a portion of the source code to a program slice of the plurality of program slices, wherein the program slice comprises a program statement associated with a vulnerability;

generate, using a predictive machine learning model, a vulnerability prediction for the source code file, the vulnerability prediction comprising: (a) a location of vulnerable code in the source code based on the matching, and (b) a vulnerability class, of a plurality of vulnerability classes, associated with the vulnerable code in the source code, wherein: (i) the vulnerability prediction indicates whether the source code file increases a susceptibility to a malicious attack, (ii) the predictive machine learning model comprises a multiclass classification machine learning model and is trained based on a training dataset, and (iii) the training dataset is generated by:

(1) receiving a plurality of training source code files and the plurality of vulnerability classes associated with the plurality of training source code files,

(2) receiving a plurality of syntax features corresponding to the plurality of vulnerability classes,

(3) determining a program slicing criterion based on the plurality of syntax features,

(4) extracting a set of program slices from the plurality of training source code files based on the program slicing criterion, wherein one or more program slices of the set of program slices is extracted by performing a forward slice or a backward slice, and

(5) labeling the set of program slices with the plurality of vulnerability classes; and

initiate one or more prediction-based actions based on the vulnerability prediction.

17 . The one or more non-transitory computer-readable storage media of claim 16 , wherein:

(i) determining the program slicing criterion further comprises determining a plurality of potential vulnerability candidates by performing static analysis on a plurality of program statements associated with the plurality of training source code files and matching the plurality of program statements associated with the plurality of training source code files with the plurality of syntax features,

(ii) the program slicing criterion comprises a set of variables corresponding to a plurality of values that are required to be preserved,

(iii) the forward slice comprises a program statement affected by the program slicing criterion, and

(iv) the backward slice comprises a program statement that affects the program slicing criterion.

18 . The one or more non-transitory computer-readable storage media of claim 17 , wherein the static analysis comprises generating, for a training source code file of the plurality of training source code files, at least one of: a program dependency graph, a data dependency graph, and a control dependency graph.

19 . The one or more non-transitory computer-readable storage media of claim 16 , wherein extracting the plurality of program slices comprises generating a source code subset, the source code subset comprising the program statement from the plurality of training source code files contributing to the vulnerability.

20 . The one or more non-transitory computer-readable storage media of claim 16 , wherein the training dataset is further generated by replacing names of functions and variables in the plurality of program slices with symbolic names.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2023
From: SAHU, MONIKA
To: OPTUM, INC.
Reel/Frame 063133/0315 →
Continuity (1)
Related Publication 20240330455A1 · Oct 3, 2024
References Cited (24)
US 10817604B1 · Kimball · 2020 [cited by examiner]
US 20070074177A1 · Kurita · 2007 [cited by examiner]
US 20210256426A1 · Calvano · 2021 [cited by applicant]
US 20220004642A1 · Pujar et al. · 2022 [cited by applicant]
US 20220292200A1 · Zou et al. · 2022 [cited by applicant]
US 20230177170A1 · Olson · 2023 [cited by examiner]
US 20240265101A1 · Sydow · 2024 [cited by examiner]
CN 111753303A · 2020 [cited by applicant]
CN 113672931A · 2021 [cited by applicant]
“CVE Program,” The Mitre Corporation, (1999), (2 pages), (online), [Retrieved from the Internet Jun. 12, 2023] <URL: https://cve.mitre.org/. [cited by applicant]
“National Vulnerability Database,” National Institute of Standards and Technology, (2018), (3 pages), [Retrieved from the Internet Jun. 12, 2023] <URL: https://nvd.nist.gov/>. [cited by applicant]
“NIST Software Assurance Reference Dataset,” National Institute of Standards and Technology, U.S. Department of Commerce, (2018), (2 pages), [Retrieved from the Internet Jun. 12, 2023] <URL: https://samate.nist.gov/SRD/… [cited by applicant]
Cheng, Xiao et al. “DeepWukong: Statically Detecting Software Vulnerabilities Using Deep Graph Neural Network,”. ACM Transactions on Software Engineering and Methodology (TOSEM), vol. 1, No. 1, Article 1, Jan. 2020, pp.… [cited by applicant]
Lerch, Johannes. “On the Scalability of Static Program Analysis to Detect Vulnerabilities in the Java Platform,” Technical University of Darmstadt, Doctoral Dissertation, May 24, 2016, (135 pages), available online: htt… [cited by applicant]
Li, Zhen et al. “SySeVR: A Framework for Using Deep Learning to Detect Software Vulnerabilities,” arXiv preprint arXiv: 1807.06756v3 [cs.LG], Jan. 12, 2021, pp. 1-15, available online: https://arxiv.org/pdf/1807.06756.p… [cited by applicant]
Li, Zhen et al. “VulDeeLocator: A Deep Learning-Based Fine-Grained Vulnerability Detector,” arXiv preprint arXiv:2001.02350v2 [cs.CR], May 1, 2021, pp. 1-17, available online: https://arxiv.org/pdf/2001.02350.pdf. [cited by applicant]
Li, Zhen et al. “VulDeePecker: A Deep Learning-Based System For Vulnerability Detection,” Network and Distributed Systems Security (NDSS) Sympsium 201, Feb. 18-21, 2018, pp. 1-15, DOI: 10.14722/ndss/2018.23158. [cited by applicant]
Mahmood, Rahma et al. “Evaluation of Static Analysis Tools for Finding Vulnerabilities in Java and c/c++ Source Code,” arXiv preprint arXiv:1805.09040, May 23, 2018, pp. 1-7, available online: https://arxiv.org/ftp/arxi… [cited by applicant]
Sintaha, Mifta et al. “Katana: Dual Slicing-Based Context for Learning Bug Fixes,” ACM Transactions on Software Engineering and Methodology (TOSEM), vol. 1, No. 1, Jun. 2, 2022, pp. 1-22, DOI: 10.1145.nnnnnnn.nnnnnnn. [cited by applicant]
Tip, Frank. “A Survey of Program Slicing Techniques,” Journal of Programming Languages, vol. 3, (1995), pp. 121-189, available online: https://www.franktip.org/pubs/jpl1995.pdf. [cited by applicant]
Wang, Lu et al. “PreNNsem: A Heterogeneous Ensemble Learning Framework for Vulnerability Detection in Software,” Applied Sciences, vol. 10, No. 22:7954, Nov. 10, 2020, pp. 1-17m DOI: 10.3390/app10227954. [cited by applicant]
Wichmann, B.A. et al. “Industrial Perspective on Static Analysis,” Software Engineering Journal, vol. 10, pp. 69-75, Mar. 1995, available online: https://www.researchgate.net/profile/William-Marsh-2/publication/3407322_… [cited by applicant]
Wu, Jiajie. “Literature Review on Vulnerability Detection Using NLP Technology,” arXiv preprint arXiv:2104.11230v1 [cs.CR], Apr. 23, 2021, (10 pages), available online: https://arxiv.org/pdf/2104.11230.pdf. [cited by applicant]
Zagane, Mohammad et al. “Deep Learning for Software Vulnerabilities Detection Using Code Metrics,” IEEE Access, vol. 8, Apr. 17, 2020, pp. 74562-74570, DOI: 10.1109/ACCESS.2020.2988557. [cited by applicant]