IP Library Patent Application 15312644
Patent Application
App. No. 15/312,644

POINT-WISE PROTECTION OF APPLICATION USING RUNTIME AGENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/312,644
Abstract

Example embodiments disclosed herein relate to generating a point-wise protection based capable of being implemented using a runtime agent. Security information including line of code information associated with possible vulnerabilities are processed to determine vulnerability solution recommendations. A vulnerability solution recommendation is presented. The point-wise protection is generated based on a selection input for the vulnerability solution recommendation, where the point-wise protection is capable of being implemented using a runtime agent.

Claims (38)

1 . A computing system comprising:

an assessment engine to process security information including possible vulnerabilities of an application to determine respective vulnerability solution recommendations for the possible vulnerabilities, wherein the security information further includes the possible vulnerabilities as well as line of code information associated with the respective possible vulnerabilities;

an interface engine to present at least one of the respective vulnerability solution recommendations and to receive selection input for the one vulnerability solution recommendation; and

a patch engine to generate respective point-wise protection based on the selection input and the processed security information capable of being implemented using a runtime agent to protect a second application corresponding to the application.

2 . The computing system of claim 1 ,

wherein implementation of the point-wise protection causes the runtime agent to execute the point-wise protection when a point of a code of the second application is reached that is associated with one of the possible vulnerabilities corresponding to the at least one of the respective vulnerability solutions.

3 . The computing system of claim 2 ,

wherein implementation of the point-wise protection includes adding a security check.

4 . The computing system of claim 3 ,

wherein if the security check is failed, a security action is taken via the runtime agent.

5 . The computing system of claim 4 ,

wherein implementation of the point-wise protection functionally replaces at least part of the code of the second application.

6 . The computing system of claim 1 , further comprising:

a static code analysis engine to determine the possible vulnerabilities and the respective line of code information from statically analyzing code of the application.

7 . The computing system of claim 6 , further comprising:

a communication engine to receive the code via a web interface.

8 . The computing system of claim 1 , wherein the point-wise protection further includes code entered via the interface engine.

9 . A non-transitory machine-readable storage medium storing instructions that, if executed by at least one processor of a computing system, cause the computing system to:

determine possible vulnerabilities and respective line of code information about the possible vulnerabilities by statically analyzing code of a first application;

determine at least one vulnerability solution recommendation for at least one of the possible vulnerabilities;

present the at least one respective vulnerability solution recommendation;

receive selection input for one of the at least one vulnerability solution recommendations; and

generate respective point-wise protection based on the selection input and the at least one respective vulnerability solution recommendation capable of being implemented using a runtime agent to protect a second application corresponding to the application.

10 . The non-transitory machine-readable storage medium of claim 9 , wherein the second application is of a same version as the first application.

11 . The non-transitory machine-readable storage medium of claim 9 , wherein implementation of the point-wise protection causes the runtime agent to execute the point-wise protection when a point of a code of the second application is reached that is associated with the point-wise at least one possible vulnerability.

12 . The non-transitory machine-readable storage medium of claim 11 ,

wherein implementation of the point-wise protection includes adding a security check.

13 . The non-transitory machine-readable storage medium of claim 11 ,

wherein implementation of the point-wise protection functionally replaces at least part of the code of the second application and executes protection code by the runtime agent.

14 . A method comprising:

determining vulnerabilities and respective line of code information about the vulnerabilities by statically analyzing code of a first application;

determining at least one vulnerability solution recommendation for at least one of the vulnerabilities;

presenting the at least one respective vulnerability solution recommendation;

receiving selection input for one of the at least one vulnerability solution recommendation; and

generating a respective point-wise protection based on the selection input and the at least one respective vulnerability solution recommendation,

wherein the point-wise protection is capable of being executed by a runtime agent configured to be used with a second application of a same version as the first application, and

wherein the point-wise protection is to execute by the runtime agent when a point of a code of the second application is reached that is associated with the at least one vulnerability.

15 . A method of claim 14 , wherein implementation of the point-wise protection functionally replaces at least part of the code of the second application.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2016
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 040923/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2016
From: MADOU, MATIAS; SECHMAN, RONALD JOSEPH; SUM, SAM NG MING
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 040382/0233 →