IP Library › Granted Patent US 12,701,133
Granted Patent B2
US 12,701,133 · App. 18/883,275 · Granted Aug 4, 2026

Scanning of codebases for vulnerable cloud resource dependencies

Inventor: Nitesh Surana (Bengaluru, IN)
Assignee: Trend Micro Incorporated
H04L63/1433H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,701,133
App. No.
18/883,275
Filed
Sep 12, 2024
Granted
Aug 4, 2026
Kind
B2
Art Unit
2409
USPC
726/22
Abstract

Vulnerable cloud resource dependencies are identified in codebases. A codebase is scanned for references to one or more cloud resources. Untrusted cloud resources are identified by comparing the referenced cloud resources to an inventory of trusted cloud resources. An untrusted cloud resource is detected to be vulnerable to a cyberattack in response to determining that a subdomain of the untrusted cloud resource cannot be resolved to an Internet Protocol (IP) address by a Domain Name System (DNS) server and can be registered with a cloud service provider.

Claims (38)

1 . A method of scanning a codebase to identify dependencies on vulnerable cloud resources, the method comprising:

identifying a plurality of trusted cloud resources that are accessible over a computer network;

receiving a codebase from a codebase repository;

scanning a source code of the codebase to detect one or more cloud resources that are referenced in the source code by way of a subdomain and that are accessible over the computer network;

for each detected cloud resource, flagging the detected cloud resource as an untrusted cloud resource responsive to determining that the detected cloud resource is not one of the plurality of trusted cloud resources; and

for each untrusted cloud resource, detecting that the untrusted cloud resource is vulnerable to being exploited by a cyberattack in response to determining that the subdomain of the untrusted cloud resource cannot be resolved into an Internet Protocol (IP) address by a Domain Name System (DNS) server and that the subdomain of the untrusted cloud resource can be registered with a cloud service provider.

2 . The method of claim 1 , further comprising:

raising an alert responsive to detecting that the untrusted cloud resource is vulnerable to being exploited by a cyberattack.

3 . The method of claim 2 , wherein raising the alert includes sending a notification to an administrator.

4 . The method of claim 1 , wherein the codebase repository is a version control platform.

5 . The method of claim 1 , wherein the plurality of trusted cloud resources is hosted on a cloud computing platform.

6 . The method of claim 5 , wherein the plurality of trusted cloud resources is identified on the cloud computing platform by a Cloud Security Posture Management (CSPM) tool that is hosted on the cloud computing platform.

7 . A computer system comprising at least one processor and a memory, the memory of the computer system storing instructions that when executed by the at least one processor of the computer system cause the computer system to:

receive a codebase from a codebase repository;

scan a source code of the codebase to detect one or more cloud resources that are referenced in the code source code by way of a subdomain and that are accessible over a computer network;

for each detected cloud resource, flag the detected cloud resource as an untrusted cloud resource responsive to determining that the detected cloud resource is not in an inventory of a plurality of trusted cloud resources; and

for each untrusted cloud resource, detect that the untrusted cloud resource is vulnerable to being exploited by a cyberattack in response to determining that the subdomain of the untrusted cloud resource cannot be resolved into an Internet Protocol (IP) address by a Domain Name System (DNS) server and that the subdomain of the untrusted cloud resource can be registered with a cloud service provider.

8 . The computer system of claim 7 , wherein the instructions stored in the memory of the computer system when executed by the at least one processor of the computer system cause the computer system to:

raise an alert responsive to detecting that the untrusted cloud resource is vulnerable to being exploited by a cyberattack.

9 . The computer system of claim 8 , wherein the alert includes a notification that is sent to another computer.

10 . The computer system of claim 7 , wherein the codebase repository is a version control platform.

11 . The computer system of claim 7 , wherein the plurality of trusted cloud resources is hosted on a cloud computing platform.

12 . The computer system of claim 11 , wherein the plurality of trusted cloud resources is identified on the cloud computing platform by a Cloud Security Posture Management (CSPM) tool that is hosted on the cloud computing platform.

13 . A method of scanning a codebase to identify dependencies on vulnerable cloud resources, the method comprising:

scanning a source code of a codebase for references to cloud resources that are accessible over a computer network;

detecting a referenced cloud resource that is referenced in the source code of of the codebase by way of a subdomain of the referenced cloud resource;

comparing the referenced cloud resource to an inventory of trusted cloud resources; and

detecting that the referenced cloud resource is vulnerable to being exploited by a cyberattack based at least in response to determining that the referenced cloud resource is not listed in the inventory of trusted cloud resources and that the subdomain of the referenced cloud resource cannot be resolved into an Internet Protocol (IP) address by a Domain Name System (DNS) server.

14 . The method of claim 13 , further comprising:

further detecting that the referenced cloud resource is vulnerable to being exploited by a cyberattack in response to determining that the subdomain of the referenced cloud resource can be registered with a cloud service provider.

15 . The method of claim 13 , further comprising:

raising an alert responsive to detecting that the referenced cloud resource is vulnerable to a cyberattack.

16 . The method of claim 15 , wherein raising the alert includes sending a notification to another computer.

17 . The method of claim 13 , further comprising:

receiving the codebase from a codebase repository.

18 . The method of claim 17 , wherein the codebase repository is a version control platform.

19 . The method of claim 13 , wherein the trusted cloud resources in the inventory are hosted on a cloud computing platform.

20 . The method of claim 19 , wherein the trusted cloud resources in the inventory are identified on the cloud computing platform by a Cloud Security Posture Management (CSPM) tool that is hosted on the cloud computing platform.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2024
From: SURANA, NITESH
To: TREND MICRO INCORPORATED
Reel/Frame 068587/0046 →
Priority Claims (1)
IN 202411045840 · Jun 13, 2024 · national
Continuity (1)
Related Publication 20250385932A1 · Dec 18, 2025
References Cited (25)
US 11245717B1 · Edwards · 2022 [cited by examiner]
US 20200042712A1 · Foo · 2020 [cited by examiner]
US 20200065160A1 · Park · 2020 [cited by examiner]
US 20210141717A1 · Ananthapur Bache · 2021 [cited by examiner]
US 20230122784A1 · Khan · 2023 [cited by examiner]
US 20230130115A1 · Liu · 2023 [cited by examiner]
US 20230185922A1 · Sullivan · 2023 [cited by examiner]
US 20240281539A1 · Cao · 2024 [cited by examiner]
US 20250047687A1 · Duan · 2025 [cited by examiner]
US 20250141907A1 · Modasiya · 2025 [cited by examiner]
US 20250310367A1 · du Preez · 2025 [cited by examiner]
US 20250371136A1 · Weizman · 2025 [cited by examiner]
Marco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara, Matteo Maffei, TU Wien, Università Ca' Foscari Venezia, “Can I Take Your Subdomain? Exploring Related-Domain Attacks in the Modern Web”, Dec. 3, 2020. [cited by applicant]
Eric Pauley, Ryan Sheatsley, Blaine Hoak, Quinn Burke, Yohan Beugin, Patrick McDaniel, “Measuring and Mitigating the Risk of IP Reuse on Public Clouds”, In 43 [cited by applicant]
Daiping Liu, Shuai Hao, Haining Wang, “All Your DNS Records Point to Us, Understanding the Security Threats of Dangling DNS Records”, University of Delaware, College of William and Mary, Downloaded Dec. 9, 2024. [cited by applicant]
Gafnit Amiga, “Azure Cloud Shell Command Injection Stealing User's Access Tokens”,https://web.archive.org/web/20230929043103/https:/blog.lightspin.io/azure-cloud-shell-command-injection-stealing-users-access-tokens, Sep… [cited by applicant]
Scott Lindh, “AWS/S3 Subdomain Takeover”, Medium, InfoSec Write-ups, https://infosecwriteups.com/aws-s3-subdomain-takeover-79d705cc3553, Jan. 17, 2024. [cited by applicant]
“EdOverflow/can-i-take-over-xyz, Can I take over XYZ?—a list of services and how to claim (sub)domains with dangling DNS records”, GitHub, https://github.com/EdOverflow/can-i-take-over-xyz, Downloaded Apr. 9, 2024. [cited by applicant]
“A Guide To Subdomain Takeovers”, Hackerone Community Blog, Application Security, Hacker Resources, https://www.backerone.com/hackerone-community-blog/guide-subdomain-takeovers, Aug. 15, 2018. [cited by applicant]
“Microsoft Azure MCR VSTS CLI vstscli Uncontrolled Search Path Element Remote Code Execution Vulnerability, ZDI-24-208 ZDI-CAN-23012”, Zero Day Initiative, https://www.zerodayinitiative.com/advisories/ZDI-24-208/, Feb. … [cited by applicant]
“Prevent dangling DNS entries and avoid subdomain takeover”, Microsoft Learn, https://learn.microsoft.com/en-us/azure/security/fundamentals/subdomain-takeover, Mar. 27, 2024. [cited by applicant]
“Domain name registrar”, Wikipedia, https://en.wikipedia.org/wiki/Domain_name_registrar, Downloaded Apr. 11, 2024. [cited by applicant]
Matt Bryant, Bishop Fox Alumnus, “Fishing the AWS IP Pool for Dangling Domains”, Bishop Fox, https://bishopfox.com/blog/fishing-the-aws-ip-pool-for-dangling-domains, Oct. 7, 2015. [cited by applicant]
“‘Zero-Days’ Without Incident—Compromising Angular via Expired npm Publisher Email Domains”, The Hacker Blog, https://thehackerblog.com/zero-days-without-incident-compromising-angular-via-expired-npm-publisher-email-dom… [cited by applicant]
“Measuring and Mitigating the Risk of IP Reuse on Public Clouds”, https://arxiv.org/abs/2204.05122, Submitted on Apr. 11, 2022, Downloaded May 8, 2024. [cited by applicant]