IP Library › Granted Patent US 12,619,735
Granted Patent B2
US 12,619,735 · App. 18/191,834 · Granted May 5, 2026

Performing action based on mapping of runtime resource to hierarchy of assets utilized during development of code

Inventors: Lavanya U. Kasarabada (Woodinville, WA); Sarika Calla (Kirkland, WA); Ayala Miller (Bellevue, WA); Laveesh Rohra (Seattle, WA); Jose Miguel Parrella Romero (Sammamish, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,735
App. No.
18/191,834
Filed
Mar 28, 2023
Granted
May 5, 2026
Kind
B2
Art Unit
2496
USPC
726/1
Abstract

Techniques are described herein that are capable of performing an action based on mapping of a runtime resource to a hierarchy of assets utilized during development of code. A hierarchy of assets that are utilized during development of code on a user machine is identified (e.g., automatically identified). The assets in the hierarchy are included in respective hierarchical levels that correspond to respective asset types. A runtime resource, which is created by deployment of the code on a server machine that is coupled to the user machine via a network, is mapped (e.g., automatically mapped) to the assets in the hierarchy. An action is performed with regard to an identified asset, which is included among the assets in the hierarchy, based at least on the runtime resource being mapped to the identified asset.

Claims (103)

1 . A system comprising:

memory; and

a processing system coupled to the memory, the processing system configured to:

automatically identify a hierarchy that includes assets that are utilized during development of code on a user machine such that the assets in the hierarchy are included in respective hierarchical levels that correspond to respective asset types, wherein a first asset in a higher hierarchical level of the hierarchy includes a second asset in a lower hierarchical level of the hierarchy;

map a runtime resource, which is created by deployment of the code on a server machine that is coupled to the user machine via a network, to the assets in the hierarchy based at least on the assets being utilized during development of the code and further based at least on the runtime resource being created by the deployment of the code;

generate a graphical user interface that includes a plurality of interface elements representing a plurality of respective runtime resources that includes the runtime resource that is created by deployment of the code on the server machine, the interface elements configured such that selection of the interface elements initiates monitoring of the respective runtime resources for security vulnerabilities;

receive an instruction that indicates selection of an interface element representing the runtime resource that is created by deployment of the code on the server machine;

initiate monitoring of the runtime resource that is created by deployment of the code on the server machine for security vulnerabilities as a result of receiving the instruction;

identify a security vulnerability associated with the runtime resource as a result of the runtime resource being monitored;

as a result of the runtime resource being mapped to an asset in the hierarchy, identify the asset as a source of the security vulnerability; and

as a result of the asset being identified as the source of the security vulnerability associated with the runtime resource, address the security vulnerability by performing a remedial action with regard to the asset.

2 . The system of claim 1 , wherein the processing system is configured to:

add start scripts to a beginning of respective jobs in a build of the code and end scripts to an end of the respective jobs,

the start scripts configured to query a daemon for first information regarding assets that are built prior to performance of the respective jobs,

the end scripts configured to query the daemon for second information regarding assets that are built and pushed by the respective jobs and third information regarding assets that are pulled during the build of the code,

the second information indicating the hierarchy of the assets; and

automatically identify the hierarchy of the assets by reviewing the second information.

3 . The system of claim 2 , wherein the processing system is configured to:

trigger extraction of logs associated with the end scripts based at least on a build completion event, which indicates completion of the build of the code,

wherein a first subset of the logs includes the second information,

wherein a second subset of the logs includes the third information; and

filter the logs to obtain the first subset of the logs, which includes the second information, and to disregard the second subset of the logs, which includes the third information.

4 . The system of claim 1 , wherein the processing system is configured to:

automatically map the runtime resource to the assets in the hierarchy based at least on the assets being utilized during development of the code and further based at least on the runtime resource being created by the deployment of the code; and

perform the action with regard to the asset based at least on the runtime resource being automatically mapped to the asset.

5 . The system of claim 1 , wherein the processing system is configured to:

assign a unique identifier to the runtime resource;

assign a plurality of identifiers to the assets in the hierarchy;

map the unique identifier assigned to the runtime resource to the plurality of identifiers assigned to the assets in the hierarchy; and

perform the action with regard to the asset based at least on the unique identifier assigned to the runtime resource being mapped to an identifier assigned to the asset; and

wherein the plurality of identifiers includes the identifier assigned to the asset.

6 . The system of claim 1 , wherein the processing system is configured to:

automatically identify the hierarchy of the assets that are utilized during the development of the code by analyzing a build of the code;

store a representation of the hierarchy in a store;

identify a representation of the asset in the representation of the hierarchy that is stored in the store; and

perform the action with regard to the asset based at least on identification of the representation of the asset in the representation of the hierarchy that is stored in the store.

7 . The system of claim 1 , wherein the processing system is configured to:

establish an asset-specific policy that defines a rule to be enforced with regard to the asset; and

wherein the asset-specific policy is specific to the asset.

8 . The system of claim 1 , wherein the processing system is configured to:

provide a notification to a developer of the code via a graphical user interface, the notification suggesting an action to be initiated by the developer with regard to the asset to mitigate the security vulnerability.

9 . A method implemented by a computing system, the method comprising:

automatically identifying a hierarchy that includes assets that are utilized during development of code on a user machine such that the assets in the hierarchy are included in respective hierarchical levels that correspond to respective asset types, wherein a first asset in a higher hierarchical level of the hierarchy includes a second asset in a lower hierarchical level of the hierarchy;

mapping a runtime resource, which is created by deployment of the code on a server machine that is coupled to the user machine via a network, to the assets in the hierarchy based at least on the assets being utilized during development of the code and further based at least on the runtime resource being created by the deployment of the code;

generating a graphical user interface that includes a plurality of interface elements representing a plurality of respective runtime resources that includes the runtime resource that is created by deployment of the code on the server machine, the interface elements configured such that selection of the interface elements initiates monitoring of the respective runtime resources for security vulnerabilities;

receiving an instruction from a developer of the code, the instruction indicating selection of an interface element representing the runtime resource that is created by deployment of the code on the server machine;

initiating monitoring of the runtime resource that is created by deployment of the code on the server machine for security vulnerabilities as a result of receiving the instruction from the developer;

identifying a security vulnerability associated with the runtime resource as a result of monitoring the runtime resource;

as a result of the runtime resource being mapped to an asset in the hierarchy, mapping the security vulnerability to the asset; and

as a result of the security vulnerability being mapped to the asset, addressing the security vulnerability by performing a remedial action with regard to the asset.

10 . The method of claim 9 , further comprising:

adding start scripts to a beginning of respective jobs in a build of the code and end scripts to an end of the respective jobs,

the start scripts configured to query a daemon for first information regarding assets that are built prior to performance of the respective jobs,

the end scripts configured to query the daemon for second information regarding assets that are built and pushed by the respective jobs and third information regarding assets that are pulled during the build of the code,

the second information indicating the hierarchy of the assets;

wherein automatically identifying the hierarchy of the assets is performed by reviewing the second information.

11 . The method of claim 10 , wherein automatically identifying the hierarchy of the assets further comprises:

triggering extraction of logs associated with the end scripts based at least on a build completion event, which indicates completion of the build of the code,

wherein a first subset of the logs includes the second information,

wherein a second subset of the logs includes the third information; and

filtering the logs to obtain the first subset of the logs, which includes the second information, and to disregard the second subset of the logs, which includes the third information.

12 . The method of claim 9 , wherein performing the remedial action comprises:

performing the remedial action with regard to a repository from which the code is deployed based at least on the runtime resource being mapped to the repository; and

wherein the assets in the hierarchy include the repository.

13 . The method of claim 9 , wherein mapping the runtime resource comprises:

mapping a container image, which includes the code and additional code that enables the code to run, to the assets in the hierarchy based at least on the assets being utilized during development of the code and further based at least on the container image being created by the deployment of the code; and

wherein performing the action comprises:

performing the action with regard to the asset based at least on the container image being mapped to the asset.

14 . The method of claim 9 , wherein mapping the runtime resource to the assets in the hierarchy comprises:

mapping a plurality of runtime resources, which are created by deployment of the code on the server machine, to the assets in the hierarchy based at least on the assets being utilized during development of the code and further based at least on the plurality of runtime resources being created by the deployment of the code;

wherein the method further comprises:

receiving a request for an indication of runtime resources that are associated with the asset; and

wherein performing the action comprises:

generating a message, which indicates the plurality of runtime resources, in response to the request, based at least on the plurality of runtime resources being mapped to the asset.

15 . The method of claim 9 , further comprising:

configuring the graphical user interface to include a first interface element representing the runtime resource and a second interface element representing the asset;

wherein an arrangement of the first interface element and the second interface element in the graphical user interface indicates a relationship between the runtime resource and the asset.

16 . The method of claim 9 , wherein performing the remedial action comprises:

changing a configuration of the asset.

17 . The method of claim 9 , wherein the first asset in the higher hierarchical level is a build of the code; and

wherein the second asset in the lower hierarchical level is a line of the code.

18 . A computer program product comprising a computer-readable storage medium having instructions recorded thereon for enabling a processor-based system to perform operations, the operations comprising:

automatically identifying a hierarchy that includes assets that are utilized during development of code on a user machine such that the assets in the hierarchy are included in respective hierarchical levels that correspond to respective asset types, wherein a first asset in a higher hierarchical level of the hierarchy includes a second asset in a lower hierarchical level of the hierarchy;

mapping a runtime resource, which is created by deployment of the code on a server machine that is coupled to the user machine via a network, to the assets in the hierarchy based at least on the assets being utilized during development of the code and further based at least on the runtime resource being created by the deployment of the code;

generating a graphical user interface that includes a plurality of interface elements representing a plurality of respective runtime resources that includes the runtime resource that is created by deployment of the code on the server machine, the interface elements configured such that selection of the interface elements initiates monitoring of the respective runtime resources for security vulnerabilities;

receiving an instruction that indicates selection of an interface element representing the runtime resource that is created by deployment of the code on the server machine;

initiating monitoring of the runtime resource that is created by deployment of the code on the server machine for security vulnerabilities as a result of receiving the instruction;

identifying a security vulnerability associated with the runtime resource as a result of the runtime resource being monitored;

as a result of the runtime resource being mapped to an asset in the hierarchy, identifying the asset as a source of the security vulnerability; and

as a result of the asset being identified as the source of the security vulnerability associated with the runtime resource, addressing the security vulnerability by performing a remedial action with regard to the asset.

19 . The computer program product of claim 18 , wherein the first asset in the higher hierarchical level is a repository from which the code is deployed; and

wherein the second asset in the lower hierarchical level is a branch of the code.

20 . The computer program product of claim 18 , wherein the operations further comprise:

adding start scripts to a beginning of respective jobs in a build of the code and end scripts to an end of the respective jobs,

the start scripts configured to query a daemon for first information regarding assets that are built prior to performance of the respective jobs,

the end scripts configured to query the daemon for second information regarding assets that are built and pushed by the respective jobs and third information regarding assets that are pulled during the build of the code,

the second information indicating the hierarchy of the assets; and

wherein automatically identifying the hierarchy of the assets is performed by reviewing the second information.

21 . The computer program product of claim 20 , wherein automatically identifying the hierarchy of the assets further comprises:

triggering extraction of logs associated with the end scripts based at least on a build completion event, which indicates completion of the build of the code,

wherein a first subset of the logs includes the second information,

wherein a second subset of the logs includes the third information; and

filtering the logs to obtain the first subset of the logs, which includes the second information, and to disregard the second subset of the logs, which includes the third information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2023
From: KASARABADA, LAVANYA U.; CALLA, SARIKA; MILLER, AYALA; ROHRA, LAVEESH; PARRELLA ROMERO, JOSE MIGUEL
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 063137/0446 →
Continuity (1)
Related Publication 20240330475A1 · Oct 3, 2024
References Cited (25)
US 10579806B1 · Pyo · 2020 [cited by examiner]
US 11288061B1 · Johnson · 2022 [cited by applicant]
US 12015630B1 · Cross · 2024 [cited by examiner]
US 20140244488A1 · Kim et al. · 2014 [cited by applicant]
US 20160217423A1 · Magnan · 2016 [cited by examiner]
US 20190052729A1 · Zhou · 2019 [cited by examiner]
US 20220311794A1 · Maya · 2022 [cited by applicant]
US 20230305896A1 · Wood · 2023 [cited by examiner]
US 20240045786A1 · Bell · 2024 [cited by examiner]
US 20240291724A1 · Saha · 2024 [cited by examiner]
CN 112041832A · 2020 [cited by examiner]
WO WO2019095936A1 · 2019 [cited by examiner]
WO 2022119693A1 · 2022 [cited by applicant]
“About webhooks”, Retrieved From: https://docs.github.com/en/developers/webhooks-and-events/webhooks/about-webhooks, Retrieved on: Oct. 6, 2022, 2 Pages. [cited by applicant]
“Docker Images”, Retrieved From: https://docs.docker.com/engine/reference/commandline/images/#list-the-most-recently-created-images, Retrieved on: Oct. 6, 2022, 9 Pages. [cited by applicant]
“Metadata syntax for GitHub Actions”, Retrieved From: https://docs.github.com/en/actions/creating-actions/metadata-syntax-for-github-actions#runspre, Retrieved on: Oct. 6, 2022, 19 Pages. [cited by applicant]
“Webhook Events and Payloads”, Retrieved From: https://docs.github.com/en/developers/webhooks-and-events/webhooks/webhook-events-and-payloads#/workflow_run, Retrieved on: Oct. 6, 2022, 94 Pages. [cited by applicant]
“Webhooks All Tiers”, Retrieved From: https://docs.gitlab.com/ee/user/project/integrations/webhooks.html, Retrieved on: Oct. 6, 2022, 7 Pages. [cited by applicant]
Andrica, et al., “Service hooks events”, Retrieved From: https://learn.microsoft.com/en-us/azure/devops/service-hooks/events?view=azure-devops#build.complete, Dec. 13, 2022, 69 Pages. [cited by applicant]
Cooper, et al., “Author a pipeline decorator”, Retrieved From: https://learn.microsoft.com/en-us/azure/devops/extend/develop/add-pipeline-decorator?view=azure-devops, Jan. 28, 2023, 9 Pages. [cited by applicant]
Danielson, et al., “Integrate with Service Hooks”, Retrieved From: https://learn.microsoft.com/en-us/azure/devops/service-hooks/overview?view=azure-devops, Nov. 28, 2022, 10 Pages. [cited by applicant]
Gunda, et al., “Azure Cosmos DB service quotas”, Retrieved From: https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/cosmos-db/concepts-limits.md#azure-cosmos-db-service-quotas, Retrieved on: Oct. 6, 2022, 14… [cited by applicant]
Mader, et al., “Task Types & Usage”, Retrieved From: https://learn.microsoft.com/en-us/azure/devops/pipelines/process/tasks?view=azure-devops&tabs=yaml#/task-control-options, Dec. 22, 2022, 8 Pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/019617, Jul. 23, 2024, 15 pages. [cited by applicant]
International Preliminary Report on Patentability (Chapter I) received for PCT Application No. PCT/US2024/019617, (Ms# 412673-PCT01) Oct. 9, 2025, 10 pages. [cited by applicant]