IP Library › Granted Patent US 12,591,684
Granted Patent B2
US 12,591,684 · App. 17/646,854 · Granted Mar 31, 2026

Centralized security analysis and management of source code in network environments

Inventor: Asaf Hecht (Tel Aviv, IL)
Assignee: CyberArk Software Ltd.
G06F21/577G06F8/70G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,591,684
App. No.
17/646,854
Granted
Mar 31, 2026
Kind
B2
Abstract

Disclosed embodiments relate to systems and methods for centrally analyzing and managing source code. Techniques include identifying, at a centralized resource in a network environment, a first source code; identifying the first source code as a candidate for an execution of an access control action; identifying, at the centralized resource, a security risk indication for the first source code, the security risk indication being based on permissions associated with a functionality of the first source code; performing, based on the security risk indication, at least one of: developing a least privilege set of permissions for the source code, or modifying the least privilege set of permissions.

Claims (46)

1 . A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for centrally analyzing and managing source code, the operations comprising:

identifying, at a centralized resource in a network environment, a first source code;

identifying the first source code as a candidate for an execution of an access control action, wherein identifying the first source code is triggered by the first source code being uploaded, pushed, or changed in the network environment;

identifying, at the centralized resource, a security risk indication for the first source code, the security risk indication being based on a multifactor analysis of the first source code, wherein the multifactor analysis is based on at least two or more of: an identity requesting execution of the first source code, a source of the first source code, a permission associated with a functionality of the first source code, an embedded credential within the first source code, or an authentication status of the first source code;

performing, based on the security risk indication, at least one of:

developing a least privilege set of permissions for the source code,

modifying the least privilege set of permissions,

determining whether to execute the first source code at the centralized resource, or

determining execution conditions for execution of the first source code at the centralized resource.

2 . The non-transitory computer readable medium of claim 1 , wherein the performing is additionally based on a security context.

3 . The non-transitory computer readable medium of claim 2 , further comprising determining, at the centralized resource, a security context for the first source code, the security context being based on an analysis of the first source code, the analysis being based on at least one of:

API calls associated with the first source code,

an action type of the first source code,

current properties of the first source code,

historic properties of the first source code, or

developer properties of the first source code.

4 . The non-transitory computer readable medium of claim 3 , wherein the current properties of the first source code include at least one of: properties associated with changes made to the first code, properties associated with the first source code development environment, or properties associated with the first source code length.

5 . The non-transitory computer readable medium of claim 3 , wherein the historic properties of the first source code include at least one of: properties associated with the first source code execution history, or properties associated with a level of historic permissions associated with the first source code.

6 . The non-transitory computer readable medium of claim 3 , wherein the developer properties of the first source code include at least one of: the developer identity, the changes made by the developer to the first source code, or the developer permissions compliance profile.

7 . The non-transitory computer readable medium of claim 1 , wherein the security risk indication is determined based on application programming interface (API) calls.

8 . The non-transitory computer readable medium of claim 1 , wherein the centralized resource is a permission analysis resource.

9 . The non-transitory computer readable medium of claim 1 , wherein identifying the first source code includes at least one of: integrating with a repository containing the first source code to receive the first source code, receiving a request notification from a repository containing the first source code, or executing periodic scans of the source code repository.

10 . The non-transitory computer readable medium of claim 1 , wherein the operations further comprise identifying a network credentials vault for use in retrieving a credential for use by the first source code.

11 . The non-transitory computer readable medium of claim 1 , wherein the performing is implemented on a just-enough-administration basis with respect to execution of the first source code.

12 . The non-transitory computer readable medium of claim 1 , wherein the operations further comprise fetching a credential for the first source code.

13 . A computer-implemented method for centrally analyzing and managing scripts, the method comprising:

identifying, at a centralized resource in a network environment, a first source code;

identifying the first source code as a candidate for an execution of an access control action, wherein identifying the first source code is triggered by the first source code being uploaded, pushed, or changed in the network environment;

identifying, at the centralized resource, a security risk indication for the first source code, the security risk indication being based on a multifactor analysis of the first source code, wherein the multifactor analysis is based on at least two or more of: an identity requesting execution of the first source code, a source of the first source code, a permission associated with a functionality of the first source code, an embedded credential within the first source code, or an authentication status of the first source code;

performing, based on the security risk indication, at least one of:

developing a least privilege set of permissions for the source code,

modifying the least privilege set of permissions,

determining whether to execute the first source code at the centralized resource, or

determining execution conditions for execution of the first source code at the centralized resource.

14 . The computer-implemented method of claim 13 , wherein the first source code is a serverless code instance.

15 . The computer-implemented method of claim 13 , wherein the performing is implemented on a just-in-time basis with respect to execution of the first source code.

16 . The computer-implemented method of claim 13 , further comprising determining, at the centralized resource, a security context for the first source code, the security context being based on an analysis of the first source code, the analysis being based on at least one of:

API calls contained in the first source code,

an action type of the first source code,

current properties of the first source code,

historic properties of the first source code, or

developer properties of the first source code.

17 . The computer-implemented method of claim 16 , wherein identifying of the security risk comprises determining whether the security risk indication is exceeding a risk score.

18 . The computer-implemented method of claim 16 , wherein the security context is based on a static analysis of the first source code.

19 . The computer-implemented method of claim 16 , further comprising generating a report displaying at least one of: the security risk indication and a security context.

20 . The computer-implemented method of claim 19 , wherein the report further includes a description of functionality associated with the first source code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2022
From: HECHT, ASAF
To: CYBERARK SOFTWARE LTD.
Reel/Frame 058531/0683 →
Continuity (2)
Continuation In Part 16774294 · Jan 28, 2020
Related Publication 20220129564A1 · Apr 28, 2022
References Cited (33)
US 8572368B1 · Deacon · 2013 [cited by examiner]
US 8745616B1 · Deacon · 2014 [cited by examiner]
US 8931084B1 · Paya et al. · 2015 [cited by applicant]
US 9501643B1 · Zakorzhevsky et al. · 2016 [cited by applicant]
US 10230749B1 · Rostami-Hesarsorkh et al. · 2019 [cited by applicant]
US 10579796B1 · Neel · 2020 [cited by applicant]
US 10599635B1 · Gunn et al. · 2020 [cited by applicant]
US 10599834B1 · Stoletny · 2020 [cited by applicant]
US 10678917B1 · Witten et al. · 2020 [cited by applicant]
US 20070028303A1 · Brennan · 2007 [cited by applicant]
US 20090083731A1 · Sobel · 2009 [cited by examiner]
US 20110219448A1 · Sreedharan et al. · 2011 [cited by applicant]
US 20140033276A1 · Wibbeler · 2014 [cited by applicant]
US 20150331789A1 · Ekambaram et al. · 2015 [cited by applicant]
US 20160180086A1 · Ladikov et al. · 2016 [cited by applicant]
US 20170322929A1 · Hussain et al. · 2017 [cited by applicant]
US 20170353496A1 · Pai et al. · 2017 [cited by applicant]
US 20180048647A1 · Favila et al. · 2018 [cited by applicant]
US 20180373876A1 · El-Moussa · 2018 [cited by applicant]
US 20190007458A1 · Shulman · 2019 [cited by examiner]
US 20190079750A1 · Foskett et al. · 2019 [cited by applicant]
US 20190080081A1 · Goodridge · 2019 [cited by examiner]
US 20190180028A1 · Seo · 2019 [cited by applicant]
US 20200014713A1 · Paul et al. · 2020 [cited by applicant]
US 20200183818A1 · Guenther · 2020 [cited by examiner]
US 20210232680A1 · Hecht · 2021 [cited by applicant]
US 20210234875A1 · Hecht · 2021 [cited by applicant]
EP 2975534A1 · 2016 [cited by applicant]
WO WO2015026971A2 · 2015 [cited by applicant]
Communication and Search Report, issued from the European Patent Office in corresponding Application No. 20159761.4-1218/3660714, dated Aug. 18, 2020 (8 pages). [cited by applicant]
Threat Analysis Report Save Yourself Malware, Virus Bulletin, Oct. 2019. [cited by applicant]
Bayer et al., Dynamic analysis of malicious code, Springer-Velag 2006. [cited by applicant]
Sikorski et al., Practical Malware Analysis: A Hands-On Guide to Dissecting Malicious Software, No. Starch Press, 2012, pp. 179-204. [cited by applicant]
Cited By (1)
US 12,688,305