IP Library › Granted Patent US 12,639,158
Granted Patent B2
US 12,639,158 · App. 18/796,462 · Granted May 26, 2026

System and method for maintaining and securing software code

Inventors: Jack Bishop (Evanston, IL); Adam B. Richman (Charlotte, NC); Jason Conrad Starin (Huntersville, NC); Nathaniel Clark (Wheaton, IL); Ryan Francis Muzzo (St. Charles, IL); Timothy Andrew Wright (Bracknell, GB)
Assignee: Bank of America Corporation
G06F11/0793G06F11/0706G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,158
App. No.
18/796,462
Granted
May 26, 2026
Kind
B2
Abstract

A system includes a memory configured to store a software codebase and an instance of vulnerabilities associated with the software codebase. The system further includes a processor coupled to the memory and configured to access the software codebase and execute a scan to identify sets of metadata associated with the software codebase. The processor is configured to execute a first machine-learning model trained to generate a prediction of feature clusters based on the sets of metadata. The plurality of feature clusters includes a ratio of a vulnerability to a time-intensiveness associated with remediating the vulnerability. The processor is configured to execute a second machine-learning model trained to generate a prediction of associations between the plurality of feature clusters and the instance of vulnerabilities. The prediction of associations includes an estimate of a time-intensiveness for remediating the instance of vulnerabilities.

Claims (40)

1 . A system, comprising:

a memory configured to store a software codebase of at least one software application and an instance of one or more vulnerabilities associated with the software codebase; and

one or more processors operably coupled to the memory and configured to:

access the software codebase of the at least one software application;

execute, based on the software codebase, one or more code scans configured to identify one or more sets of metadata associated with the software codebase, wherein the identified one or more sets of metadata comprises an indication of one or more vulnerabilities associated with the software codebase;

execute a first machine-learning model trained to generate a prediction of a plurality of feature clusters based at least in part on the identified one or more sets of metadata, wherein each of the plurality of feature clusters comprises a ratio of a vulnerability to a time-intensiveness associated with remediating the vulnerability;

train a clustering machine-learning algorithm based at least in part on a data set of technical support requests requesting remediation of instances of the one or more vulnerabilities;

execute, in response to the training of the clustering machine-learning algorithm, a clustering machine-learning model to generate a prediction of one or more associations between each of the plurality of feature clusters and the instance of one or more vulnerabilities associated with the software codebase, wherein the prediction of the one or more associations comprises an estimate of a time-intensiveness for remediating the instance of one or more vulnerabilities associated with the software codebase;

output, by the clustering machine-learning model, the estimate of the time-intensiveness for remediating the instance of one or more vulnerabilities associated with the software codebase; and

patch the software codebase based at least in part on the estimate of the time-intensiveness to resolve the instance of one or more vulnerabilities associated with the software codebase.

2 . The system of claim 1 , wherein the estimate of a time-intensiveness comprises a confidence score by which a remediation of the instance of one or more vulnerabilities is to be compared.

3 . The system of claim 1 , wherein the identified one or more sets of metadata comprises metadata associated with one or more of a development history of the software codebase, a remediation history of the software codebase, a maturity level of the software codebase, or a coding style of the software codebase.

4 . The system of claim 1 , wherein the first machine-learning model comprises one or more of a supervised machine-learning model or a semi-supervised machine-learning model trained to generate the prediction of the plurality of feature clusters.

5 . The system of claim 1 , wherein the instance of one or more vulnerabilities associated with the software codebase is identified based on a static application security testing (SAST) scan of the software codebase, and wherein the SAST scan of the software codebase was executed during one or more of an implementation phase of the at least one software application, a development phase of the at least one software application, or a testing phase of the at least one software application.

6 . The system of claim 1 , wherein the one or more processors are further configured to deploy the patched software codebase.

7 . A method, comprising:

accessing a software codebase of at least one software application;

executing, based on the software codebase, one or more code scans configured to identify one or more sets of metadata associated with the software codebase, wherein the identified one or more sets of metadata comprises an indication of one or more vulnerabilities associated with the software codebase;

executing a first machine-learning model trained to generate a prediction of a plurality of feature clusters based at least in part on the identified one or more sets of metadata, wherein each of the plurality of feature clusters comprises a ratio of a vulnerability to a time-intensiveness associated with remediating the vulnerability;

training a clustering machine-learning algorithm based at least in part on a data set of technical support requests requesting remediation of instances of the one or more vulnerabilities;

executing, in response to the training of the clustering machine-learning algorithm, a clustering machine-learning model to generate a prediction of one or more associations between each of the plurality of feature clusters and an instance of one or more vulnerabilities associated with the software codebase, wherein the prediction of the one or more associations comprises an estimate of a time-intensiveness for remediating the instance of one or more vulnerabilities associated with the software codebase;

outputting, by the clustering machine-learning model, the estimate of the time-intensiveness for remediating the instance of one or more vulnerabilities associated with the software codebase; and

patching the software codebase based at least in part on the estimate of the time-intensiveness to resolve the instance of one or more vulnerabilities associated with the software codebase.

8 . The method of claim 7 , wherein the estimate of a time-intensiveness comprises a confidence score by which a remediation of the instance of one or more vulnerabilities is to be compared.

9 . The method of claim 7 , wherein the identified one or more sets of metadata comprises metadata associated with one or more of a development history of the software codebase, a remediation history of the software codebase, a maturity level of the software codebase, or a coding style of the software codebase.

10 . The method of claim 7 , wherein the first machine-learning model comprises one or more of a supervised machine-learning model or a semi-supervised machine-learning model trained to generate the prediction of the plurality of feature clusters.

11 . The method of claim 7 , wherein the instance of one or more vulnerabilities associated with the software codebase is identified based on a static application security testing (SAST) scan of the software codebase, and wherein the SAST scan of the software codebase was executed during one or more of an implementation phase of the at least one software application, a development phase of the at least one software application, or a testing phase of the at least one software application.

12 . The method of claim 7 , further comprising deploying the patched software codebase.

13 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a system, cause the one or more processors to:

access a software codebase of at least one software application;

execute, based on the software codebase, one or more code scans configured to identify one or more sets of metadata associated with the software codebase, wherein the identified one or more sets of metadata comprises an indication of one or more vulnerabilities associated with the software codebase;

execute a first machine-learning model trained to generate a prediction of a plurality of feature clusters based at least in part on the identified one or more sets of metadata, wherein each of the plurality of feature clusters comprises a ratio of a vulnerability to a time-intensiveness associated with remediating the vulnerability;

train a clustering machine-learning algorithm based at least in part on a data set of technical support requests requesting remediation of instances of the one or more vulnerabilities;

execute, in response to the training of the clustering machine-learning algorithm, a clustering machine-learning model to generate a prediction of one or more associations between each of the plurality of feature clusters and an instance of one or more vulnerabilities associated with the software codebase, wherein the prediction of the one or more associations comprises an estimate of a time-intensiveness for remediating the instance of one or more vulnerabilities associated with the software codebase;

output, by the clustering machine-learning model, the estimate of the time-intensiveness for remediating the instance of one or more vulnerabilities associated with the software codebase; and

patch the software codebase based at least in part on the estimate of the time-intensiveness to resolve the instance of one or more vulnerabilities associated with the software codebase.

14 . The non-transitory computer-readable medium of claim 13 , wherein the estimate of a time-intensiveness comprises a confidence score by which a remediation of the instance of one or more vulnerabilities is to be compared.

15 . The non-transitory computer-readable medium of claim 13 , wherein the identified one or more sets of metadata comprises metadata associated with one or more of a development history of the software codebase, a remediation history of the software codebase, a maturity level of the software codebase, or a coding style of the software codebase.

16 . The non-transitory computer-readable medium of claim 13 , wherein the first machine-learning model comprises one or more of a supervised machine-learning model or a semi-supervised machine-learning model trained to generate the prediction of the plurality of feature clusters.

17 . The non-transitory computer-readable medium of claim 13 , wherein the instance of one or more vulnerabilities associated with the software codebase is identified based on a static application security testing (SAST) scan of the software codebase, and wherein the SAST scan of the software codebase was executed during one or more of an implementation phase of the at least one software application, a development phase of the at least one software application, or a testing phase of the at least one software application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2024
From: BISHOP, JACK; RICHMAN, ADAM B.; STARIN, JASON CONRAD; CLARK, NATHANIEL; MUZZO, RYAN FRANCIS; WRIGHT, TIMOTHY ANDREW
To: BANK OF AMERICA CORPORATION
Reel/Frame 068206/0144 →
Continuity (1)
Related Publication 20260044403A1 · Feb 12, 2026
References Cited (21)
US 9069737B1 · Kimotho et al. · 2015 [cited by applicant]
US 9386034B2 · Cochenour · 2016 [cited by applicant]
US 10747651B1 · Vanderwall et al. · 2020 [cited by applicant]
US 10868825B1 · Dominessy et al. · 2020 [cited by applicant]
US 10970395B1 · Bansal et al. · 2021 [cited by applicant]
US 10997015B2 · Singh et al. · 2021 [cited by applicant]
US 11121872B2 · Digiambattista et al. · 2021 [cited by applicant]
US 11379219B2 · Bhalla et al. · 2022 [cited by applicant]
US 11888890B2 · Maheve et al. · 2024 [cited by applicant]
US 11954112B2 · Siebel et al. · 2024 [cited by applicant]
US 20180018602A1 · DiMaggio et al. · 2018 [cited by applicant]
US 20190280942A1 · Côtéet al. · 2019 [cited by applicant]
US 20190303726A1 · Côtéet al. · 2019 [cited by applicant]
US 20210035116A1 · Berrington et al. · 2021 [cited by applicant]
US 20220121455A1 · Hoban et al. · 2022 [cited by applicant]
US 20220210200A1 · Crabtree et al. · 2022 [cited by applicant]
US 20230113621A1 · Griffin et al. · 2023 [cited by applicant]
US 20230195560A1 · Haririan · 2023 [cited by examiner]
US 20230274587A1 · Gronsbell et al. · 2023 [cited by applicant]
US 20230325272A1 · Golden et al. · 2023 [cited by applicant]
US 20240045713A1 · Webb · 2024 [cited by examiner]