IP Library › Granted Patent US 12,443,397
Granted Patent B2
US 12,443,397 · App. 19/169,671 · Granted Oct 14, 2025

Techniques for code fingerprinting

Inventors: Eshel Yaron (Amsterdam, NL); Barak Bercovitz (Even-Yehuda, IL); Tomer Schwartz (Tel Aviv, IL)
Assignee: Wiz, Inc.
G06F8/36G06F8/35
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,443,397
App. No.
19/169,671
Granted
Oct 14, 2025
Kind
B2
Abstract

A system and method for code fingerprinting. A method includes scanning a code repository including software components by executing fingerprinting code on the code repository in order to generate statistics vectors for the software components. The fingerprinting code includes instructions for performing a text search to identify instances of patterns in the code repository and to generate the statistics vectors based on the identified pattern instances. The statistics vectors are clustered with respect to groupings of software components. The statistics vectors are aggregated by combining values of respective statistics in the statistics vectors belonging to the same clusters. An anomaly is detected based on the aggregated statistics vectors. One or more remedial actions are performed with respect to the software components based on the detected anomaly.

Claims (48)

1. A method for anomaly remediation, comprising:

scanning a code repository including a plurality of software components by executing fingerprinting code on the code repository in order to generate a plurality of statistics vectors for the plurality of software components, wherein each statistics vector includes a plurality of values representing statistics for respective aspects of a corresponding software component of the plurality of software components, wherein the fingerprinting code includes instructions that configure a processing circuitry to perform a text search in order to identify instances of patterns in the code repository and to generate the plurality of statistics vectors based on the identified instances of patterns when the fingerprinting code is executed;

clustering the plurality of statistics vectors into a plurality of clusters defined with respect to a plurality of software component groupings, wherein each cluster of the plurality of clusters includes a subset of the plurality of statistics vectors of corresponding to a subset of the plurality of software components which belongs to one of the plurality of software component groupings;

aggregating the plurality of statistics vectors into a plurality of aggregated statistics vectors by combining values of respective statistics in statistics vectors among the plurality of statistics vectors belonging to a same cluster of the plurality of clusters;

detecting at least one anomaly based on the plurality of aggregated statistics vectors; and

performing at least one remedial action with respect to the plurality of software components based on the detected at least one anomaly.

2. The method of claim 1 , wherein the fingerprinting code is generated based on a knowledge base including a plurality of nodes representing respective software components of the plurality of software components, wherein the patterns are defined with respect to the knowledge base.

3. The method of claim 2 , further comprising:

querying the knowledge base in order to obtain query results; and

generating the fingerprinting code is based on the query results.

4. The method of claim 2 , wherein the knowledge base is queried for at least one string of text of the plurality of nodes of the plurality of software components represented in the knowledge base, wherein the patterns are defined with respect to the at least one string of text.

5. The method of claim 2 , wherein the knowledge base is queried in a first query, wherein the query results are a first set of query results, wherein the plurality of statistics vectors is a first plurality of statistics vectors, wherein the at least one anomaly is at least one first anomaly, further comprising:

updating the fingerprinting code by querying the knowledge base in a second query in order to obtain a second set of query results and regenerating the fingerprinting code based on the second set of query results;

scanning the code repository using the updated fingerprinting code in order to generate a second plurality of statistics vectors; and

detecting at least one second anomaly based on the second plurality of statistics vectors.

6. The method of claim 2 , wherein the knowledge base includes data of code of the plurality of software components, wherein the patterns are defined further with respect to the data of the code of the plurality of software components.

7. The method of claim 1 , wherein the patterns are patterns in text, wherein the fingerprinting code includes instructions that, when executed by a processing circuitry, configure the processing circuitry to perform at least one text search.

8. The method of claim 1 , wherein the plurality of statistics vectors include a plurality of counts vectors, wherein each of the plurality of values of each counts vector is a count of instances for a respective aspect of the plurality of software components represented in a knowledge base.

9. The method of claim 1 , further comprising:

applying a machine learning model to the plurality of aggregated statistics vectors in order to obtain a set of machine learning model outputs, wherein the machine learning model is trained using training statistical data for a knowledge base including a plurality of nodes representing respective software components of the plurality of software components, wherein the machine learning model is trained to output anomalies when applied to the plurality of aggregated statistics vectors, wherein the at least one anomaly is detected based on the set of machine learning model outputs.

10. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

scanning a code repository including a plurality of software components by executing fingerprinting code on the code repository in order to generate a plurality of statistics vectors for the plurality of software components, wherein each statistics vector includes a plurality of values representing statistics for respective aspects of a corresponding software component of the plurality of software components, wherein the fingerprinting code includes instructions that configure a processing circuitry to perform a text search in order to identify instances of patterns in the code repository and to generate the plurality of statistics vectors based on the identified instances of patterns when the fingerprinting code is executed;

clustering the plurality of statistics vectors into a plurality of clusters defined with respect to a plurality of software component groupings, wherein each cluster of the plurality of clusters includes a subset of the plurality of statistics vectors of corresponding to a subset of the plurality of software components which belongs to one of the plurality of software component groupings;

aggregating the plurality of statistics vectors into a plurality of aggregated statistics vectors by combining values of respective statistics in statistics vectors among the plurality of statistics vectors belonging to a same cluster of the plurality of clusters;

detecting at least one anomaly based on the plurality of aggregated statistics vectors; and

performing at least one remedial action with respect to the plurality of software components based on the detected at least one anomaly.

11. A system for anomaly remediation, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

scanning a code repository including a plurality of software components by executing fingerprinting code on the code repository in order to generate a plurality of statistics vectors for the plurality of software components, wherein each statistics vector includes a plurality of values representing statistics for respective aspects of a corresponding software component of the plurality of software components, wherein the fingerprinting code includes instructions that configure a processing circuitry to perform a text search in order to identify instances of patterns in the code repository and to generate the plurality of statistics vectors based on the identified instances of patterns when the fingerprinting code is executed;

clustering the plurality of statistics vectors into a plurality of clusters defined with respect to a plurality of software component groupings, wherein each cluster of the plurality of clusters includes a subset of the plurality of statistics vectors of corresponding to a subset of the plurality of software components which belongs to one of the plurality of software component groupings;

aggregate the plurality of statistics vectors into a plurality of aggregated statistics vectors by combining values of respective statistics in statistics vectors among the plurality of statistics vectors belonging to a same cluster of the plurality of clusters;

detect at least one anomaly based on the plurality of aggregated statistics vectors; and

perform at least one remedial action with respect to the plurality of software components based on the detected at least one anomaly.

12. The system of claim 11 , wherein the fingerprinting code is generated based on a knowledge base including a plurality of nodes representing respective software components of the plurality of software components, wherein the patterns are defined with respect to the knowledge base.

13. The system of claim 12 , wherein the system is further configured to:

query the knowledge base in order to obtain query results; and

generate the fingerprinting code is based on the query results.

14. The system of claim 12 , wherein the knowledge base is queried for at least one string of text of the plurality of nodes of the plurality of software components represented in the knowledge base, wherein the patterns are defined with respect to the at least one string of text.

15. The system of claim 12 , wherein the knowledge base is queried in a first query, wherein the query results are a first set of query results, wherein the plurality of statistics vectors is a first plurality of statistics vectors, wherein the at least one anomaly is at least one first anomaly, wherein the system is further configured to:

update the fingerprinting code by querying the knowledge base in a second query in order to obtain a second set of query results and regenerating the fingerprinting code based on the second set of query results;

scan the code repository using the updated fingerprinting code in order to generate a second plurality of statistics vectors; and

detect at least one second anomaly based on the second plurality of statistics vectors.

16. The system of claim 12 , wherein the knowledge base includes data of code of the plurality of software components, wherein the patterns are defined further with respect to the data of the code of the plurality of software components.

17. The system of claim 11 , wherein the patterns are patterns in text, wherein the fingerprinting code includes instructions that, when executed by a processing circuitry, configure the processing circuitry to perform at least one text search.

18. The system of claim 11 , wherein the plurality of statistics vectors include a plurality of counts vectors, wherein each of the plurality of values of each counts vector is a count of instances for a respective aspect of the plurality of software components represented in a knowledge base.

19. The system of claim 11 , wherein the system is further configured to:

apply a machine learning model to the plurality of aggregated statistics vectors in order to obtain a set of machine learning model outputs, wherein the machine learning model is trained using training statistical data for a knowledge base including a plurality of nodes representing respective software components of the plurality of software components, wherein the machine learning model is trained to output anomalies when applied to the plurality of aggregated statistics vectors, wherein the at least one anomaly is detected based on the set of machine learning model outputs.

Continuity (2)
Continuation 18593470 · Mar 1, 2024
Related Publication 20250278255A1 · Sep 4, 2025
References Cited (64)
US 8806425B1 · Willis · 2014 [cited by examiner]
US 9052961B2 · Mangtani · 2015 [cited by examiner]
US 9449042B1 · Evans · 2016 [cited by examiner]
US 10108803B2 · Chari et al. · 2018 [cited by applicant]
US 11429353B1 · Liguori et al. · 2022 [cited by applicant]
US 11893106B2 · Kim et al. · 2024 [cited by applicant]
US 20030131284A1 · Flanagan · 2003 [cited by examiner]
US 20090222479A1 · Burukhin et al. · 2009 [cited by applicant]
US 20100070448A1 · Omoigui · 2010 [cited by applicant]
US 20130167241A1 · Siman · 2013 [cited by examiner]
US 20150341214A1 · Croy · 2015 [cited by examiner]
US 20150347759A1 · Cabrera et al. · 2015 [cited by applicant]
US 20150363197A1 · Carback et al. · 2015 [cited by applicant]
US 20160379480A1 · OlmstedThompson et al. · 2016 [cited by applicant]
US 20170075749A1 · Ambichl et al. · 2017 [cited by applicant]
US 20170185785A1 · Vorona et al. · 2017 [cited by applicant]
US 20170249128A1 · Fojtik et al. · 2017 [cited by applicant]
US 20170286692A1 · Nakajima et al. · 2017 [cited by applicant]
US 20180025160A1 · Hwang et al. · 2018 [cited by applicant]
US 20180129479A1 · McPherson et al. · 2018 [cited by applicant]
US 20180285199A1 · Mitkar et al. · 2018 [cited by applicant]
US 20180321918A1 · Mcclory et al. · 2018 [cited by applicant]
US 20180373507A1 · Mizrahi et al. · 2018 [cited by applicant]
US 20190007290A1 · He et al. · 2019 [cited by applicant]
US 20190068622A1 · Lin et al. · 2019 [cited by applicant]
US 20190294477A1 · Koppes · 2019 [cited by examiner]
US 20190303579A1 · Reddy et al. · 2019 [cited by applicant]
US 20190354389A1 · Du et al. · 2019 [cited by applicant]
US 20200097662A1 · Hufsmith et al. · 2020 [cited by applicant]
US 20200183766A1 · Kumar-Mayernik et al. · 2020 [cited by applicant]
US 20200296117A1 · Karpovsky et al. · 2020 [cited by applicant]
US 20210042096A1 · White, III et al. · 2021 [cited by applicant]
US 20210168165A1 · Alsaeed et al. · 2021 [cited by applicant]
US 20210182387A1 · Zhu et al. · 2021 [cited by applicant]
US 20210311855A1 · Khan et al. · 2021 [cited by applicant]
US 20210382997A1 · Yi et al. · 2021 [cited by applicant]
US 20220114023A1 · Choksi et al. · 2022 [cited by applicant]
US 20220129539A1 · Walsh et al. · 2022 [cited by applicant]
US 20220311794A1 · Maya et al. · 2022 [cited by applicant]
US 20220327220A1 · Sharma et al. · 2022 [cited by applicant]
US 20220353341A1 · Östrand et al. · 2022 [cited by applicant]
US 20230036739A1 · Deppisch et al. · 2023 [cited by applicant]
US 20230118065A1 · Kumar · 2023 [cited by applicant]
US 20230130649A1 · Schwartz et al. · 2023 [cited by applicant]
US 20230229781A1 · Stolbikov et al. · 2023 [cited by applicant]
US 20230297366A1 · Wigglesworth et al. · 2023 [cited by applicant]
US 20230333845A1 · Zand et al. · 2023 [cited by applicant]
US 20250013442A1 · Hempstead · 2025 [cited by examiner]
EP 3208996A1 · 2017 [cited by applicant]
EP 3494506A1 · 2019 [cited by applicant]
WO 2023067423A1 · 2023 [cited by applicant]
Alrabaee, “A Survey of Binary Code Fingerprinting Approaches: Taxonomy, Methodologies, and Features”, 2022, ACM (Year: 2022). [cited by examiner]
Liu, “VFDETECT: A Vulnerable Code Clone Detection System Based on Vulnerability Fingerprint”, 2017, IEEE (Year: 2017). [cited by examiner]
Doan TP, Jung S. DAVS: Dockerfile Analysis for Container Image Vulnerability Scanning. CMC-Computers Materials & Continua. Jan. 1, 2022;72(1):1699-711. Jan. 1, 2022 (Jan. 1, 2022). [cited by applicant]
International Search Report for PCT Application No. PCT/IB2022/059483. The International Bureau of WIPO. [cited by applicant]
International Search Report for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
International Search Report for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]
International Search Report, PCT/IB2023/052415; Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
Written Opinion of the International Searching Authority for PCT Application No. PCT/IB2022/059483 dated Jan. 8, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the International Searching Authority, PCT/IB2023/052415. Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
Written Opinion of the Searching Authority for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]
International Search Report for PCT/IB2025/051650, dated May 26, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2025/051650, dated May 26, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]