IP Library › Granted Patent US 12,572,448
Granted Patent B2
US 12,572,448 · App. 18/361,424 · Granted Mar 10, 2026

Leveraging code churn analytics to optimize sanitizer performance

Inventors: Soumitra Chatterjee (Karnataka, IN); Ritanya Bhaskar Bharadwaj (Karnataka, IN); Veena Konnanath (Karnataka, IN)
Assignee: Hewlett Packard Enterprise Development LP
G06F11/3644G06F8/433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,572,448
App. No.
18/361,424
Granted
Mar 10, 2026
Kind
B2
Abstract

Systems and methods sanitize computer code. In particular, fragile portions of computer code are identified based on instances of bug/defect-related churn data associated with the computer code. A control flow graph representative of the computer code may be generated, the control flow graph including nodes and edges. Nodes whose source location falls within the reported fragile sections are identified, and may be flagged as being susceptible. Thereafter, a sanitizer is run on the flagged nodes.

Claims (44)

1 . A method comprising:

identifying instances of bug/defect-related churn data associated with a source code file;

identifying a number of bug/defect-related churn data instances associated with each source code line of the source code file;

clustering data within a data structure representing the source code line with data representing consecutive source code line of the source code file to form a clustered data representing source code lines based on similarity of numbers of bug/defect-related churn data instances associated with the consecutive source code line;

ranking the clusters of data:

wherein the ranking of the clusters is at least based on the numbers of bug/defect-related churn data instances;

selecting highest ranked clusters of data as suspect source code ranges;

generating a control flow graph comprising nodes and edges;

flagging as susceptible, those nodes associated with a source code location within the suspect source code ranges; and

running a sanitizer on the nodes flagged as being susceptible.

2 . The method of claim 1 , wherein generating the control flow graph comprising nodes and edges is part of a normal compilation process.

3 . The method of claim 1 , wherein flagging as susceptible, those nodes associated with the source code location within the suspect source code ranges comprises marking control flow passing through the flagged nodes as susceptible code flow and enabled for sanitizer instrumentation.

4 . The method of claim 3 , wherein instrumenting only the nodes flagged as being susceptible comprises adding sanitizer instrumentation into an executable code.

5 . The method of claim 4 , wherein instrumenting on only the nodes flagged as being susceptible comprises running the executable code with the sanitizer instrumentation enabled on only the control flow marked as susceptible code flow.

6 . A method comprising:

identifying records of bug/defect-related commits associated with a source code file;

identifying a number of bug/defect-related commit records associated with each source code line of the source code file;

clustering data within a data structure representing the source code line with data representing consecutive source code line of the source code file to form a clustered data representing source code lines based on similarity of numbers of bug/defect-related commit records associated with the consecutive source code line;

ranking the clusters of data:

wherein the ranking of the clusters is at least based on the numbers of bug/defect-related commit records;

selecting highest ranked clusters of data as suspect source code ranges;

generating a control flow graph comprising nodes and edges;

flagging as susceptible, those nodes associated with a source code location within the suspect source code ranges; and

instrumenting on the nodes flagged as being susceptible.

7 . The method of claim 6 , wherein generating the control flow graph comprising nodes and edges is part of a normal compilation process.

8 . The method of claim 6 , wherein flagging as susceptible, those nodes associated with the source code location within the suspect source code ranges comprises marking control flow passing through the flagged nodes as susceptible code flow and enabled for sanitizer instrumentation.

9 . The method of claim 8 , wherein instrumenting only the nodes flagged as being susceptible comprises building the sanitizer into an executable code.

10 . The method of claim 9 , wherein instrumenting on only the nodes flagged as being susceptible comprises running the executable code with the sanitizer instrumentation enabled on only the control flow marked as susceptible code flow.

11 . A computer system comprising:

a processor; and

a memory including instructions that, when executed by the processor, cause the processor to:

identify instances of bug/defect-related churn data associated with a source code file;

identify a number of bug/defect-related churn data instances associated with each source code line of the source code file;

cluster data within a data structure representing the source code line with data representing consecutive source code line of the source code file to form a clustered data representing source code lines based on similarity of numbers of bug/defect-related churn data instances associated with the consecutive source code line;

rank the clusters of data:

wherein the ranking of the clusters is at least based on the numbers of bug/defect-related churn data instances;

select highest ranked clusters of data as suspect source code ranges;

generate a control flow graph comprising nodes and edges;

flag as susceptible, those nodes associated with a source code location within the suspect source code ranges; and

run a sanitizer on the nodes flagged as being susceptible.

12 . The computer system of claim 11 , wherein generating the control flow graph comprising nodes and edges is part of a normal compilation process.

13 . The computer system of claim 11 , wherein flagging as susceptible, those nodes associated with the source code location within the suspect source code ranges comprises marking control flow passing through the flagged nodes as susceptible code flow and enabled for sanitizer instrumentation.

14 . The computer system of claim 13 , wherein instrumenting only the nodes flagged as being susceptible comprises adding sanitizer instrumentation into an executable code.

15 . The method of claim 14 , wherein instrumenting on only the nodes flagged as being susceptible comprises running the executable code with the sanitizer instrumentation enabled on only the control flow marked as susceptible code flow.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2023
From: CHATTERJEE, SOUMITRA; BHARADWAJ, RITANYA BHASKAR; KONNANATH, VEENA
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 064591/0650 →
Continuity (1)
Related Publication 20250036550A1 · Jan 30, 2025
References Cited (62)
US 8572748B2 · Pistoia et al. · 2013 [cited by applicant]
US 8635602B2 · Haviv et al. · 2014 [cited by applicant]
US 8667584B2 · Berg et al. · 2014 [cited by applicant]
US 8769696B2 · Pistoia et al. · 2014 [cited by applicant]
US 8898776B2 · Molnar et al. · 2014 [cited by applicant]
US 9672279B1 · Cohen · 2017 [cited by examiner]
US 9690945B2 · Tripp · 2017 [cited by applicant]
US 9892021B2 · Coyle · 2018 [cited by examiner]
US 10255046B2 · Alexander · 2019 [cited by examiner]
US 10789362B2 · Allen · 2020 [cited by examiner]
US 10896253B2 · Liu · 2021 [cited by examiner]
US 10915639B2 · Hassanshahi et al. · 2021 [cited by applicant]
US 11061811B2 · Luss · 2021 [cited by examiner]
US 11175897B1 · Deng · 2021 [cited by examiner]
US 11440190B1 · Maggi · 2022 [cited by examiner]
US 11474819B1 · Kapoor · 2022 [cited by examiner]
US 11513944B1 · Oguara · 2022 [cited by examiner]
US 11822673B2 · Araujo · 2023 [cited by examiner]
US 20140380283A1 · Hu · 2014 [cited by examiner]
US 20150363294A1 · Carback, III · 2015 [cited by examiner]
US 20170132116A1 · Lopian · 2017 [cited by examiner]
US 20170315903A1 · David · 2017 [cited by examiner]
US 20170344746A1 · Tripp · 2017 [cited by applicant]
US 20180024911A1 · Kruszewski · 2018 [cited by examiner]
US 20180330102A1 · Siman et al. · 2018 [cited by applicant]
US 20190108342A1 · Conikee · 2019 [cited by examiner]
US 20190180035A1 · Esperer · 2019 [cited by examiner]
US 20200125475A1 · Iyer · 2020 [cited by examiner]
US 20200125478A1 · Iyer · 2020 [cited by examiner]
US 20200394311A1 · Li et al. · 2020 [cited by applicant]
US 20210263728A1 · Farrier · 2021 [cited by examiner]
US 20220114076A1 · Zhou · 2022 [cited by examiner]
US 20220253377A1 · Coutinho Moraes · 2022 [cited by examiner]
US 20220261222A1 · Gopal · 2022 [cited by examiner]
US 20230004487A1 · Bitla · 2023 [cited by examiner]
US 20230025441A1 · Oguara · 2023 [cited by examiner]
US 20240303075A1 · Chatterjee et al. · 2024 [cited by applicant]
US 20240338443A1 · Miller · 2024 [cited by examiner]
WO WO2020080513A1 · 2020 [cited by examiner]
Österlund, Sebastian, et al. “{ParmeSan}: Sanitizer-guided greybox fuzzing.” 29th USENIX Security Symposium (USENIX Security 20). 2020. [cited by examiner]
Ahmadi, Mansour, et al. “Finding bugs using your own code: detecting functionally-similar yet inconsistent code.” 30th USENIX security symposium (USENIX Security 21). 2021. [cited by examiner]
Huang, Zhen, et al. “Talos: Neutralizing vulnerabilities with security workarounds for rapid response.” 2016 IEEE Symposium on Security and Privacy (SP). IEEE, 2016. [cited by examiner]
Le Goues, Claire, and Westley Weimer. “Measuring code quality to improve specification mining.” IEEE Transactions on Software Engineering 38.1 (2011). [cited by examiner]
Gjomemo, Rigel, et al. “Leveraging static analysis tools for improving usability of memory error sanitization compilers.” 2016 IEEE International Conference on Software Quality, Reliability and Security (QRS). IEEE, 201… [cited by examiner]
Kaoudis, Kelly, Henrik Brodin, and Evan Sultanik. “Automatically detecting variability bugs through hybrid control and data flow analysis.” 2023 IEEE Security and Privacy Workshops (SPW). IEEE, 2023. [cited by examiner]
Zhu, Xiaogang, and Marcel Böhme. “Regression greybox fuzzing.” Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 2021. [cited by examiner]
Padmanabhuni, Bindu Madhavi. Auditing buffer overflow vulnerabilities using program analysis and data mining techniques. Diss. 2016. [cited by examiner]
“Home · Angular”, available on <https://angular.dev/>, 2010-2025, 5 pages. [cited by applicant]
“TensorFlow”. available online at <https://web.archive.org/web/20151109150056/https://www.tensorflow.org/>, Nov. 9, 2015, 5 pages. [cited by applicant]
Github, “gcc-mirror/gcc”, available online at <https://web.archive.org/web/20140808073827/https://github.com/gcc-mirror/gcc>, Aug. 8, 2014, 3 pages. [cited by applicant]
Github, “google / sanitizers”, available online at <https://github.com/google/sanitizers/wiki>, Dec. 3, 2015, 3 pages. [cited by applicant]
Jens Weller, “Meeting C++ survey results: C++ Tooling”, Apr. 15, 2021, 4 pages. [cited by applicant]
Jira et al., “Atlassian named a Leader in the 2024 Gartner@ Magic Quadrant”, available online at <https://www.atlassian.com/software/jira>, 2025, 16 pages. [cited by applicant]
LLVM Overview, “The LLVM Compiler Infrastructure”, available online at <https://web.archive.org/web/20180309085928/https://llvm.org/>, Mar. 9, 2018, 3 pages. [cited by applicant]
Stephen Chong , CS153: Compilers Lecture 17: Control Flow Graph ? and Data Flow Analysis?, 2018, 24 pages. [cited by applicant]
Test Automation Resources, “7 Fundamental Principles of Software Testing”, available online at <https://web.archive.org/web/20190926080130/https://testautomationresources.com/software-testing-basics/fundamental-principl… [cited by applicant]
Test Automation Resources, “All Things You Need To Know About Exhaustive Testing”, available online at <https://web.archive.org/web/20200811061025/https://testautomationresources.com/software-testing-basics/exhaustive-t… [cited by applicant]
Wikipedia, “Code coverage”, available online at <https://en.wikipedia.org/w/index.php?title=Code_coverage&oldid=1035573572>, Jul. 26, 2021, 7 Pages. [cited by applicant]
Wikipedia, “Dynamic program analysis”, available online at <https://en.wikipedia.org/wiki/Dynamic_program_analysis>, Feb. 2009, 4 pages. [cited by applicant]
Wikipedia, “Instrumentation (computer programming)”, available online at <https://en.wikipedia.org/wiki/Instrumentation_%28computer_programming%29>, Dec. 2013, 2 pages. [cited by applicant]
Zhang et al., “Debloating Address Sanitizer”, 2022, 19 pages. [cited by applicant]
Zhang et al., “SANRAZOR: Reducing Redundant Sanitizer Checks in C/C++ Programs”, 15th USENIX Symposium on Operating Systems Design and Implementation. Jul. 14-16, 2021, 17 pages. [cited by applicant]