IP Library Granted Patent US 7,418,734
Granted Patent B2
US 7,418,734 · App. 10/824,684 · Granted Aug 26, 2008

Method and system for detecting privilege escalation vulnerabilities in source code

Assignee: Ounce Labs, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,418,734
App. No.
10/824,684
Granted
Aug 26, 2008
Kind
B2
Abstract

A method and system of detecting vulnerabilities in source code. Source code is parsed into an intermediate representation. Models are derived for the code and the models are then analyzed in conjunction with pre-specified rules about the routines to determine if the routine call posses one or more of pre-selected vulnerabilities.

Claims (10)

1. A method of detecting privilege escalation vulnerabilities in a pre-existing source code listing, said source code listing having a listed sequence of expressions, each expression including a set of operands and operators to transform values of the operands, said source code listing further having routine calls, said routine calls including arguments with which to invoke a routine, said source code listing being stored in computer readable medium having computer executable instructions, wherein a privilege escalation vulnerability is an uncontrolled escalation of system privileges that allows unauthorized access to system resources, the method comprising:

providing a list specifying routines that potentially cause privilege escalation vulnerabilities;

providing pre-specified ranges of values for arguments of routines in the list that cause privilege escalation vulnerabilities;

analyzing the source code listing to identify calls to routines specified in the list;

analyzing the source code listing to semantically analyze arguments of the identified routine calls to determine routine calls that possess privilege escalation vulnerabilities using the pre-specified ranges of values;

wherein semantically analyzing the arguments of the identified routine calls comprises analyzing the source code listing to create computer models of the arguments, each model specifying a range of values that each corresponding argument can take when the source code listing is executed; and

generating a report that identifies the vulnerabilities.

2. The method of claim 1 , wherein analyzing the source code listing to create computer models of the arguments comprises:

analyzing the source code listing to create computer models of said operands, each of said operand models specifying a range of values of each corresponding operand as a result of operand transformations expressed in the source code listing; and

using the operand models to create the argument models.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2010
From: OUNCE LABS, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 023950/0593 →
SECURITY INTEREST Recorded Dec 31, 2008
From: OUNCE LABS, INC.
To: SQUARE 1 BANK
Reel/Frame 022043/0977 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2004
From: BERG, RYAN JAMES; ROSE, LARRY; PEYTON, JOHN; DANAHY, JOHN J.; GOTTLIEB, ROBERT; REHBEIN, CHRIS
To: OUNCE LABS, INC.
Reel/Frame 015217/0863 →
Continuity (2)
Provisional Application 6046401900 · Apr 18, 2003
Related Publication 20050010806A1 · Jan 13, 2005