IP Library Granted Patent US 10,977,375
Granted Patent B2
US 10,977,375 · App. 16/101,119 · Granted Apr 13, 2021

Risk assessment of asset leaks in a blockchain

Inventors: Emanuele Ragnoli (Dublin, IE); John Sheehan (Dublin, IE); Stefano Braghin (Blanchardstown, IE); Gokhan Sagirlar (Varese, IT)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/577G06F8/427G06F8/433G06F21/10G06F21/563G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,977,375
App. No.
16/101,119
Granted
Apr 13, 2021
Kind
B2
Abstract

A system and method for asset leak risk assessment in blockchains are presented. A risk assessment of recursive call attack vulnerabilities may be cognitively determined according to risk vulnerability measurements generated from a computer program source code, a list of external call functions, a risk assessment function, a list of assets, a parser, or a combination thereof.

Claims (27)

1. A method for asset leak risk assessment in blockchains by a processor, comprising:

receiving, by a parser, user input data inclusive of a computer program source code, a list of external calls, a list of assets, and a risk assessment function;

generating, by the parser for the computer program source code, a list of external call functions, an execution queue, and a dependency map for one or more variables; and

cognitively determining a risk assessment of recursive call attack vulnerabilities according to risk vulnerability measurements generated from an output of the risk assessment function predicting an anomaly associated with the list of assets, wherein a comparison of the one or more variables of the list of external call functions performed for the list of external calls is utilized to identify those of the one or more variables having been suspiciously modified to generate the output, and wherein cognitively determining the risk assessment of recursive call attack vulnerabilities further includes determining a probability of depleting assets from a blockchain according to the risk vulnerability measurements.

2. The method of claim 1 , wherein cognitively determining the risk assessment of recursive call attack vulnerabilities further includes determining the risk assessment of recursive call attack vulnerabilities according to a selected call function of asset values, one or more time profiles, and a number of times a variable of the one or more variables appears in a suspicious list.

3. The method of claim 1 , further including profiling a time of an external call and generating a list of variables of the one or more variables invoked by the external call.

4. The method of claim 1 , further including generating a list of functions and profiling a time for a selected variable of the one or more variables.

5. The method of claim 1 , further including determining a vulnerability risk according to a selected function of asset values, one or more time profiles, and a number of times a variable of the one or more variables appears in a suspicious list.

6. A system for asset leak risk assessment in blockchains, comprising:

one or more computers with executable instructions that when executed cause the system to:

receive, by a parser, user input data inclusive of a computer program source code, a list of external calls, a list of assets, and a risk assessment function;

generate, by the parser for the computer program source code, a list of external call functions, an execution queue, and a dependency map for one or more variables; and

cognitively determine a risk assessment of recursive call attack vulnerabilities according to risk vulnerability measurements generated from an output of the risk assessment function predicting an anomaly associated with the list of assets, wherein a comparison of the one or more variables of the list of external call functions performed for the list of external calls is utilized to identify those of the one or more variables having been suspiciously modified to generate the output, and wherein cognitively determining the risk assessment of recursive call attack vulnerabilities further includes determining a probability of depleting assets from a blockchain according to the risk vulnerability measurements.

7. The system of claim 6 , wherein, pursuant to cognitively determining the risk assessment of recursive call attack vulnerabilities, the executable instructions further determine the risk assessment of recursive call attack vulnerabilities according to a selected call function of asset values, one or more time profiles, and a number of times a variable of the one or more variables appears in a suspicious list.

8. The system of claim 6 , wherein, pursuant to cognitively determining the risk assessment of recursive call attack vulnerabilities, the executable instructions further determine a probability of depleting assets from a blockchain according to the risk vulnerability measurements.

9. The system of claim 6 , wherein the executable instructions further profile a time of an external call and generating a list of variables of the one or more variables invoked by the external call.

10. The system of claim 6 , wherein the executable instructions further generate a list of functions and profiling a time for a selected variable of the one or more variables.

11. The system of claim 6 , wherein the executable instructions further determine a vulnerability risk according to a selected function of asset values, one or more time profiles, and a number of times a variable of the one or more variables appears in a suspicious list.

12. A computer program product for asset leak risk assessment in blockchains by a processor, the computer program product comprising a non-transitory computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions comprising:

an executable portion that receives, by a parser, user input data inclusive of a computer program source code, a list of external calls, a list of assets, and a risk assessment function;

an executable portion that generates, by the parser for the computer program source code, a list of external call functions, an execution queue, and a dependency map for one or more variables; and

an executable portion that cognitively determines a risk assessment of recursive call attack vulnerabilities according to risk vulnerability measurements generated from an output of the risk assessment function predicting an anomaly associated with the list of assets, wherein a comparison of the one or more variables of the list of external call functions performed for the list of external calls is utilized to identify those of the one or more variables having been suspiciously modified to generate the output, and wherein cognitively determining the risk assessment of recursive call attack vulnerabilities further includes determining a probability of depleting assets from a blockchain according to the risk vulnerability measurements.

13. The computer program product of claim 12 ,

further including an executable portion that determines the risk assessment of recursive call attack vulnerabilities according to a selected call function of asset values, one or more time profiles, and a number of times a variable of the one or more variables appears in a suspicious list.

14. The computer program product of claim 12 , further including an executable portion that profiles a time of an external call and generating a list of variables of the one or more variables invoked by the external call.

15. The computer program product of claim 12 , further including an executable portion that generates a list of functions and profiling a time for a selected variable of the one or more variables.

16. The computer program product of claim 12 , further including an executable portion that determining a vulnerability risk according to a selected function of asset values, one or more time profiles, a number of times a variable of the one or more variables appears in a suspicious list.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2018
From: RAGNOLI, EMANUELE; SHEEHAN, JOHN; BRAGHIN, STEFANO; SAGIRLAR, GOKHAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 046617/0922 →
Continuity (1)
Related Publication 20200050768A1 · Feb 13, 2020