IP Library Granted Patent US 12,430,220
Granted Patent B2
US 12,430,220 · App. 18/360,545 · Granted Sep 30, 2025

Software application intelligence platform, and method thereof

Inventors: Eyal Mamo (Tel Aviv, IL); Idan Ninyo (Tel Aviv-Jaffa, IL); Amir Sidis (Tel Aviv, IL); Omri Ivanir (Tel Aviv, IL)
Assignee: CrowdStrike, Inc.
G06F11/302G06F11/3051G06F11/3075G06F11/328
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,430,220
App. No.
18/360,545
Granted
Sep 30, 2025
Kind
B2
Abstract

A system and method for identifying distinct software applications. A method includes collecting, from a plurality of resources, data utilized to at least execute a plurality of software applications of an organization; analyzing the collected data to identify the plurality of software applications to determine how each of the plurality of software applications interact with its respective identified software applications to detect at least two applications that communicate with each other, wherein the detected at least two applications that communicate with each other are distinct software applications; determining, by using a static analysis process, dependencies between the distinct software applications; and compiling visibility data based on the at least identified distinct software applications and their determined dependencies.

Claims (71)

1. A method of identifying distinct software applications, comprising:

collecting, from a plurality of resources, data utilized to at least execute a plurality of software applications of an organization;

analyzing the data to identify the plurality of software applications to determine how each of the plurality of software applications interact with its respective identified software applications to detect at least two applications that communicate with each other based on matching their corresponding communication addresses, wherein the at least two applications that communicate with each other are distinct software applications;

determining, using a static analysis process, dependencies between the distinct software applications; and

compiling visibility data based on the distinct software applications and their determined dependencies.

2. The method of claim 1 , further comprising:

determining, using the static analysis process, dependencies between the software applications of the identified software applications; and

including the visibility data based on the dependencies between the software applications of the identified software applications.

3. The method of claim 2 , further comprising:

enabling a control of at least one policy based on the visibility data included in a dataflow map.

4. The method of claim 1 , wherein the determining the dependencies between the identified software applications further comprises:

traversing the data of each of the plurality of software applications to detect usage of at least one software library; and

detecting how each of the plurality of software applications interact with its respective identified software applications.

5. The method of claim 1 , wherein the analyzing the data to identify the plurality of software applications further comprises:

identifying identity details of each software application of the plurality of software applications.

6. The method of claim 5 , wherein the detecting the dependencies between the distinct software applications, further comprising:

determining, using the static analysis process, the dependencies between the identified distinct software applications based on their communication and software library usage.

7. The method of claim 1 , wherein the identifying the distinct software applications communicating with each other further comprises:

identifying a first communication address designated on at least one of an ingress interface or an egress interface of a first software application;

identifying a second communication address designated on at least one of an ingress interface or an egress interface of a second software application; and

matching the first communication address to the second communication address to determine if there is at least a partial match.

8. The method of claim 7 , wherein each communication address comprises at least one of:

an application programming interface (API);

a Uniform Resource Locator (URL); or

a route designating a resource.

9. The method of claim 1 , wherein the data comprises at least one of:

binary code;

script software libraries;

error logs;

script code;

configurations files; or

credentials.

10. A non-transitory computer readable medium having stored thereon instructions that, when executed by a processing circuitry, cause the processing circuitry to:

collect, from a plurality of resources, data utilized to at least execute a plurality of software applications of an organization;

analyze the data to identify the plurality of software applications to determine how each of the plurality of software applications interact with its respective identified software applications to detect at least two applications that communicate with each other based on matching their corresponding communication addresses, wherein the at least two applications that communicate with each other are distinct software applications;

determine, using a static analysis process, dependencies between the distinct software applications; and

compile visibility data based on the distinct software applications and their determined dependencies.

11. A system, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

collect, from a plurality of resources, data utilized to at least execute a plurality of software applications of an organization;

analyze the data to identify the plurality of software applications to determine how each of the plurality of software applications interact with its respective identified software applications to detect at least two applications that communicate with each other based on matching their corresponding communication addresses, wherein the at least two applications that communicate with each other are distinct software applications;

determine, using a static analysis process, dependencies between the distinct software applications; and

compile visibility data based on the distinct software applications and their determined dependencies.

12. The system of claim 11 , wherein the system is further configured to:

determine, using the static analysis process, dependencies between the software applications of the identified software applications; and

include the visibility data based on the dependencies between the software applications of the identified software applications.

13. The system of claim 12 , wherein the system is further configured to:

enable a control of at least one policy based on the visibility data included in a dataflow map.

14. The system of claim 11 , wherein the system is further configured to:

traverse the data of each of the plurality of software applications to detect usage of at least one software library; and

detect how each of the plurality of software applications interact with its respective identified software applications.

15. The system of claim 11 , wherein the system is further configured to:

identify identity details of each software application of the plurality of software applications.

16. The system of claim 15 , wherein the system is further configured to:

determine, using the static analysis process, the dependencies between the identified distinct software applications based on their communication and software library usage.

17. The system of claim 11 , wherein the system is further configured to:

identify a first communication address designated on at least one of an ingress interface or an egress interface of a first software application;

identify a second communication address designated on at least one of an ingress interface or an egress interface of a second software application; and

match the first communication address to the second communication address to determine if there is at least a partial match.

18. The system of claim 17 , wherein each communication address comprises at least one of:

an application programming interface (API);

a Uniform Resource Locator (URL); or

a route designating a resource.

19. The system of claim 11 , wherein the data comprises at least one of:

binary code;

script software libraries;

error logs;

script code;

configurations files; or

credentials.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2025
From: BIONIC STORK LTD.
To: CROWDSTRIKE, INC.
Reel/Frame 070147/0938 →
Continuity (2)
Continuation 17513117 · Oct 28, 2021
Related Publication 20230409457A1 · Dec 21, 2023
References Cited (11)
US 11442765B1 · Zhang et al. · 2022 [cited by applicant]
US 20110066719A1 · Miryanov et al. · 2011 [cited by applicant]
US 20180041470A1 · Schultz · 2018 [cited by examiner]
US 20180131558A1 · Sharma · 2018 [cited by examiner]
US 20200177435A1 · Sharma · 2020 [cited by applicant]
US 20200396232A1 · Lee · 2020 [cited by applicant]
US 20210218774A1 · Mittal · 2021 [cited by examiner]
EP 2431879A1 · 2012 [cited by applicant]
International Search Report for PCT Application No. PCT/IB2022/059622. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the International Searching Authority for PCT Application No. PCT/IB2022/059622 dated Dec. 6, 2022. The International Bureau of WIPO. [cited by applicant]
Extended European Search Report Dated Nov. 27, 2024 for European Patent Application No. 22886232.2, 10 pp. total. [cited by applicant]