IP Library Granted Patent US 9,892,262
Granted Patent B2
US 9,892,262 · App. 14/787,863 · Granted Feb 13, 2018

Analyzing target software for security vulnerabilities

Inventor: Michael Jason Schmitt (Sunnyvale, CA)
Assignee: EntIT Software, LLC
G06F21/577G06F8/43G06F8/77G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,892,262
App. No.
14/787,863
Filed
Oct 29, 2015
Granted
Feb 13, 2018
Kind
B2
Examiner
LEE, JASON T
Art Unit
2438
USPC
726/25
Abstract

A method of analyzing target software for security vulnerabilities comprises, with a processor, scanning a codebase of a target software using a static analysis scan to identify a number of security flaws, and calculating a number of code metrics of the codebase of the target software for a number of iterations over a period of time to obtain a number of historical scans.

Claims (32)

1. A method of analyzing target software for security vulnerabilities comprising, with a hardware processor:

at each of a plurality of iterations over a period of time:

scanning a codebase of a target software using a static analysis scan to identify security flaws;

obtaining runtime security information from a runtime environment of a version of the target software; and

calculating code metrics of the codebase of the target software;

analyzing correlations between the security flaws, the runtime security information, and the code metrics over the period of time; and

prioritizing the security flaws based on the correlations.

2. The method of claim 1 , further comprising predicting risks associated with the codebase based on the correlations between the security flaws and the code metrics over the period of time.

3. The method of claim 1 , further comprising storing the security flaws identified at each iteration and the code metrics calculated at each iteration as historical scans in a historical scan database.

4. The method of claim 1 , further comprising prioritizing the security flaws identified using the static analysis scan over the period of time that are correlated with unstable or complex areas of the codebase of the target software as identified by the code metrics over the period of time.

5. The method of claim 1 , further comprising deprioritizing the security flaws identified using the static analysis scan that are inconsistently deterministic over the period of time.

6. The method of claim 1 , further comprising prioritizing the security flaws identified using the static analysis scan over the period of time that are correlated with reused areas of the codebase of the target software as identified by the code metrics over the period of time.

7. A system for analyzing target software for security vulnerabilities comprising:

a hardware processor;

a data storage device coupled to the processor, the data storage device storing instructions executable by the hardware processor to:

scan a codebase of a target software to identify security flaws at each of a plurality of iterations over a period of time;

obtain runtime security information of the target software at each iteration over the period of time;

calculate code metrics of the codebase of the target software at each iteration over the period of time;

analyze correlations among the security flaws, the runtime security information, and the code metrics; and

prioritize the security flaws based the correlations among the security flaws, the runtime security information, and the code metrics; and

a historical scan database for storing the security flaws, the runtime security information, and the code metrics at each iteration as historical scans.

8. The system of claim 7 , wherein the instructions are executable by the hardware processor to further predict risks associated with the codebase based on the correlations among the security flaws, the runtime security information, and the code metrics.

9. The system of claim 7 , further comprising a server, in which the functionality of the system is provided as a Software as a Service (SaaS), a Platform as a Service (PaaS), a Infrastructure as a Service (IaaS), an application program interface (API) as a service (APIaaS), or combinations thereof via the server.

10. A computer program product for analyzing target software for security vulnerabilities, the computer program product comprising:

a non-transitory computer readable storage medium comprising computer usable program code embodied therewith, the computer usable program code executable by a hardware processor to:

analyze correlations among static analysis scans identifying security flaws, code metrics, and runtime security scans determined from target software at each of a plurality of iterations over a period of time; and

prioritize the security flaws based on the correlations.

11. The computer program product of claim 10 , wherein the computer usable program code is executable by the hardware processor to further predict security flaws associated with the target software based on the correlations.

12. The computer program product of claim 10 , wherein the computer usable program code is executable by the hardware processor to further:

at each iteration over the period of time, scan a codebase of the target software using static analysis to identify the security flaws in the static analysis scans; and

at each iteration over the period of time, calculate the code metrics of the codebase of the target software.

13. The computer program product of claim 10 , wherein the computer usable program code is executable by the hardware processor to further at each iteration over the period of time, obtain runtime security information from a runtime environment of the target software.

Assignments (7)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2015
From: SCHMITT, MICHAEL JASON
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 036912/0578 →
Continuity (1)
Related Publication 20160110549A1 · Apr 21, 2016