IP Library Granted Patent US 12,189,788
Granted Patent B2
US 12,189,788 · App. 18/740,976 · Granted Jan 7, 2025

Identifying and addressing potential vulnerabilities in third-party code

Inventors: Henrik Plate (Valbonne, FR); Dimitrios Styliadis (San Jose, CA); Alexandre Wilhelm (Kilauea, HI)
Assignee: Endor Labs Inc
G06F21/577G06F21/6218G06F21/552G06F21/565
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,788
App. No.
18/740,976
Filed
Jun 12, 2024
Granted
Jan 7, 2025
Kind
B2
Art Unit
2497
USPC
726/25
Abstract

A non-transitory computer-readable media, method and server for detecting and addressing vulnerabilities in a third-party code are described. In some examples, a server receives a security advisory that includes a description of a vulnerability and accesses a version control system (VCS) used by a third-party library to determine additional resources related to the vulnerability. The server determines a set of code changes performed by the project maintainers in the VCS, identifies one or more fix commits that address the vulnerability, and identifies one or more functions with the vulnerability that have been changed by the fix commits. The server performs a search for components and component versions that include the one or more functions with the vulnerability and generates an enriched vulnerability description that includes identifiers of package versions that include fixed versions of the one or more functions and vulnerable version of the one or more functions. Project code in a development system is modified to use the fixed versions of the one or more functions.

Claims (62)

1. A computer-implemented method, executed by one or more processors, comprising:

receiving a security advisory that include a description of a vulnerability;

accessing a version control system (VCS) used by a third-party library;

determining additional resources related to the vulnerability;

determining a set of code changes performed by project maintainers in the VCS;

identifying one or more fix commits that address the vulnerability;

identifying one or more functions with the vulnerability that have been changed by the one or more fix commits, wherein identification of the one or more functions with the vulnerability includes:

comparing one or more files corresponding to the one or more functions before and after a code change was made, and

identifying individual functions of the one or more functions that included the vulnerability and that have been modified to address the vulnerability;

performing a search for components and component versions that include the one or more functions with the vulnerability;

generating an enriched vulnerability description that includes identifiers of package versions that include:

fixed versions of the one or more functions; and

vulnerable version of the one or more functions; and

modifying project code in a development system to use the fixed versions of the one or more functions.

2. The computer-implemented method of claim 1 , further comprising:

determining a set of functions that are not directly related to the vulnerability; and

excluding from the search the set of functions that are not directly related to the vulnerability.

3. The computer-implemented method of claim 1 , further comprising:

identifying, using an artificial intelligence, fix commits related to the vulnerability.

4. The computer-implemented method of claim 1 , further comprising:

obtaining packages from one or more package registries; and determining whether the packages include individual functions of the one or more functions in a vulnerable form or a fixed form.

5. The computer-implemented method of claim 1 , wherein the third-party library comprises an open-source library.

6. The computer-implemented method of claim 1 , wherein: the security advisory is received from a security database.

7. A server comprising:

one or more processors; and

one or more non-transitory computer readable media storing instructions executable by the one or more processors to perform operations comprising:

receiving a security advisory that include a description of a vulnerability;

accessing a version control system (VCS) used by a third-party library;

determining additional resources related to the vulnerability;

determining a set of code changes performed by project maintainers in the VCS;

identifying one or more fix commits that address the vulnerability;

identifying one or more functions with the vulnerability that have been changed by the one or more fix commits, wherein identification of the one or more functions with the vulnerability includes:

comparing one or more files corresponding to the one or more functions before and after a code change was made, and

identifying individual functions of the one or more functions that included the vulnerability and that have been modified to address the vulnerability;

performing a search for components and component versions that include the one or more functions with the vulnerability;

generating an enriched vulnerability description that includes identifiers of package versions that include:

fixed versions of the one or more functions; and

vulnerable version of the one or more functions; and

modifying project code in a development system to use the fixed versions of the one or more functions.

8. The server of claim 7 , further comprising: determining a set of functions that are not directly related to the vulnerability; and excluding from the search the set of functions that are not directly related to the vulnerability.

9. The server of claim 7 , further comprising: identifying, using an artificial intelligence, fix commits related to the vulnerability.

10. The server of claim 7 , further comprising: obtaining packages from one or more package registries; and determining whether the packages include individual functions of the one or more functions in a vulnerable form or a fixed form.

11. The server of claim 7 wherein the third-party library comprises an open-source library.

12. The server of claim 7 , wherein the security advisory is received from a security database.

13. One or more non-transitory computer readable media capable of storing instructions executable by one or more processors to perform operations comprising:

receiving a security advisory that include a description of a vulnerability;

accessing a version control system (VCS) used by a third-party library;

determining additional resources related to the vulnerability;

determining a set of code changes performed by project maintainers in the VCS;

identifying one or more fix commits that address the vulnerability;

identifying one or more functions with the vulnerability that have been changed by the one or more fix commits, wherein identification of the one or more functions with the vulnerability includes:

comparing one or more files corresponding to the one or more functions before and after a code change was made, and

identifying individual functions of the one or more functions that included the vulnerability and that have been modified to address the vulnerability;

performing a search for components and component versions that include the one or more functions with the vulnerability;

generating an enriched vulnerability description that includes identifiers of package versions that include:

fixed versions of the one or more functions; and

vulnerable version of the one or more functions; and

modifying project code in a development system to use the fixed versions of the one or more functions.

14. The one or more non-transitory computer readable media of claim 13 , further comprising: determining a set of functions that are not directly related to the vulnerability; and excluding from the search the set of functions that are not directly related to the vulnerability.

15. The one or more non-transitory computer readable media of claim 13 , further comprising: identifying, using an artificial intelligence, fix commits related to the vulnerability.

16. The one or more non-transitory computer readable media of claim 13 , further comprising: obtaining packages from one or more package registries; and determining whether the packages include individual functions of the one or more functions in a vulnerable form or a fixed form.

17. The one or more non-transitory computer readable media of claim 13 , wherein: the third-party library comprises an open-source library; and the security advisory is received from a security database.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2024
From: PLATE, HENRIK; STYLIADIS, DIMITRIOS; WILHELM, ALEXANDRE
To: ENDOR LABS INC
Reel/Frame 067755/0753 →
Continuity (5)
Provisional Application 63552793 · Feb 13, 2024
Provisional Application 63472561 · Jun 12, 2023
Provisional Application 63472562 · Jun 12, 2023
Provisional Application 63472557 · Jun 12, 2023
Related Publication 20240411897A1 · Dec 12, 2024
References Cited (23)
US 9064134B1 · Agarwal · 2015 [cited by examiner]
US 9880832B2 · Plate · 2018 [cited by examiner]
US 10754951B1 · Tang · 2020 [cited by examiner]
US 11204690B1 · Hoberman · 2021 [cited by examiner]
US 20160099963A1 · Mahaffey · 2016 [cited by examiner]
US 20180197123A1 · Parimelazhagan · 2018 [cited by examiner]
US 20180239898A1 · Haerterich · 2018 [cited by examiner]
US 20190138717A1 · Ben-Shalom · 2019 [cited by examiner]
US 20200175174A1 · Bakalli · 2020 [cited by examiner]
US 20210056209A1 · Fox · 2021 [cited by examiner]
US 20210182391A1 · Plate · 2021 [cited by examiner]
US 20230004653A1 · Shiraishi · 2023 [cited by examiner]
US 20240241963A1 · Wareus · 2024 [cited by examiner]
CN 102681835A · 2012 [cited by examiner]
CN 104838324A · 2015 [cited by examiner]
CN 107729227A · 2018 [cited by examiner]
CN 111639019A · 2020 [cited by examiner]
CN 113127341A · 2021 [cited by examiner]
CN 115185570A · 2022 [cited by examiner]
Stephan Neuhaus, Thomas Zimmermann, Christian Holler and Andreas Zeller (Predicting Vulnerable Software Components); pp. 12; Published on Oct. 29-Nov. 2, 2007. [cited by examiner]
Wenlin Xu, Tong Li, Jinsong Wang, and Yahui Tang (Detecting vulnerable software functions via text and dependency features); pp. 11; Published online: Jan. 7, 2023. [cited by examiner]
Antonino Sabetta, Michele Bezzi, A Practical Approach to the Automatic Classification of Security-Relevant Commits, Nov. 11, 2018, 7 pages. [cited by applicant]
Daan Hommersom, Antonino Sabetta, Automated Mapping of Vulnerability Advisories onto their Fix Commits in Open Source Repositories, Mar. 24, 2021, 28 pages. [cited by applicant]