IP Library Granted Patent US 10,587,641
Granted Patent B2
US 10,587,641 · App. 15/312,645 · Granted Mar 10, 2020

Point-wise protection of application using runtime agent and dynamic security analysis

Inventors: Matias Madou (Diegem, BE); Ronald Joseph Sechman (Alpharetta, GA); Sam Ng Ming Sum (Hong Kong, CN)
Assignee: MICRO FOCUS LLC
H04L63/1433G06F21/566G06F21/577H04L63/1441G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,587,641
App. No.
15/312,645
Granted
Mar 10, 2020
Kind
B2
Abstract

Example embodiments disclosed herein relate to generating a point-wise protection based on dynamic security analysis. Vulnerability solution recommendation are provided based on the dynamic security analysis. A point-wise protection is generated based on a selection of the vulnerability solution recommendation.

Claims (40)

1. A system comprising:

a hardware processor; and

a non-transitory storage medium storing instructions executable on the hardware processor to:

perform a dynamic security analysis on an application under test (AUT) executed on a server to determine a vulnerability of the AUT, wherein the dynamic security analysis includes a communication to a first runtime agent at the server to trace information, in the dynamic security analysis, relating to a code portion of the AUT associated with the vulnerability, wherein the traced information includes line of code information that indicates a location of the code portion of the AUT associated with the vulnerability;

receive input selecting a vulnerability solution recommendation for the vulnerability;

generate a point-wise protection code based on the input; and

send the point-wise protection code to a second runtime agent, the point-wise protection code executable by the second runtime agent to run, in response to reaching a point of code of a second application during execution of the second application that is different from the AUT, replacement code in place of a code portion of the second application to alleviate the vulnerability at the second application, wherein the point-wise protection code comprises an instruction to break code execution in response to reaching the point of code of the second application indicated by the line of code information in the traced information, the running of the replacement code functionally replacing the code portion of the second application without actually replacing the code portion of the second application.

2. The system of claim 1 , wherein the generating of the point-wise protection code includes adding code to perform a security check by the second runtime agent to check the point-wise protection code and take a security action via the second runtime agent if the security check failed.

3. The system of claim 1 , wherein the instructions are executable on the hardware processor to:

provide to a second server running the second application the point-wise protection code for execution by the second runtime agent at the second server.

4. The system of claim 1 , wherein the traced information includes a point of the code portion of the AUT associated with the vulnerability.

5. The system of claim 4 , wherein the traced information includes a set of active stack frames of the AUT when the vulnerability occurred.

6. The system of claim 1 , wherein the instructions are executable on the hardware processor to present the vulnerability solution recommendation for the vulnerability as part of a plurality of vulnerability solution recommendations to a user, and the receiving of the input comprises receiving user selection of the vulnerability solution recommendation from the plurality of vulnerability solution recommendations.

7. The system of claim 6 , wherein the plurality of vulnerability solution recommendations presented to the user comprise recommended patches for respective vulnerabilities of the AUT, and the receiving of the input comprises receiving user selection of a given recommended patch of the recommended patches.

8. The system of claim 7 , wherein the instructions are executable to receive a user edit of a code of the given recommended patch to produce the replacement code.

9. The system of claim 6 , wherein the plurality of vulnerability solution recommendations presented to the user identify respective different types of vulnerabilities of the AUT.

10. A non-transitory machine-readable storage medium storing instructions that, if executed by at least one hardware processor of a computing system, cause the computing system to:

perform a dynamic security analysis test on an application under test (AUT) to determine a vulnerability of the AUT, wherein the dynamic security analysis test includes communication with a first runtime agent executing with the AUT to receive trace information relating to a code portion of the AUT, wherein the trace information includes line of code information that indicates a location of a point of the code portion of the AUT associated with the vulnerability, and a set of active stack frames of the AUT when the vulnerability occurred;

classify the vulnerability;

provide a vulnerability solution recommendation for the classified vulnerability;

receive a selection of the vulnerability solution recommendation; and

generate a point-wise protection code based on the selection, wherein the point-wise protection code is executable by a second runtime agent to run, in response to reaching a point of code of a second application during execution of the second application that is different from the AUT, replacement code in place of a code portion of the second application to address the classified vulnerability at the second application, the running of the replacement code functionally replacing the code portion of the second application without actually replacing the code portion of the second application, wherein the point of code of the second application is indicated by the line of code information in the trace information relating to the code portion of the AUT.

11. The non-transitory machine-readable storage medium of claim 10 , wherein the second application is of a same version as the AUT, and the point-wise protection code comprises an instruction to break code execution in response to reaching the point of code of the second application indicated by the line of code information, and the instructions if executed cause the computing system to further:

send the point-wise protection code to the second runtime agent, the sending of the point-wise protection code to the second runtime agent causing execution of the point-wise protection code by the second runtime agent to run the replacement code in place of the code portion of the second application to address the classified vulnerability at the second application.

12. The non-transitory machine-readable storage medium of claim 10 , wherein the providing of the vulnerability solution recommendation for the classified vulnerability comprises presenting the vulnerability solution recommendation for the classified vulnerability as part of a plurality of vulnerability solution recommendations to a user, and the receiving of the selection comprises receiving user selection of the vulnerability solution recommendation from the plurality of vulnerability solution recommendations.

13. The non-transitory machine-readable storage medium of claim 12 , wherein the plurality of vulnerability solution recommendations presented to the user comprise recommended patches for respective vulnerabilities of the AUT, and the receiving of the selection comprises receiving user selection of a given recommended patch of the recommended patches.

14. The non-transitory machine-readable storage medium of claim 13 , wherein the instructions if executed cause the computing system to receive an edit of a code of the given recommended patch to produce the replacement code.

15. A method executed by a system comprising a hardware processor, comprising:

performing a dynamic security analysis test on an application under test (AUT) to determine a vulnerability of the AUT, wherein the dynamic security analysis test includes communication with a first runtime agent executing with the AUT to receive trace information of the AUT, wherein the trace information includes line of code information that indicates a location of a code portion of the AUT, the code portion of the AUT associated with the vulnerability;

presenting, to a user, a vulnerability solution recommendation for the vulnerability;

receiving a user selection of the vulnerability solution recommendation;

generating a point-wise protection code based on the user selection; and

sending the point-wise protection code to a second runtime agent, the point-wise protection code executable by the second runtime agent to run, in response to reaching a point of code of a second application during execution of the second application that is different from the AUT, replacement code in place of a code portion of the second application to address the vulnerability at the second application, wherein the point-wise protection code comprises an instruction to break code execution in response to reaching the point of code of the second application indicated by the line of code information in the trace information, the running of the replacement code functionally replacing the code portion of the second application without actually replacing the code portion of the second application.

16. The method of claim 15 , further comprising:

receiving, by the first runtime agent, a trace request during the dynamic security analysis test;

monitoring, by the first runtime agent, execution of the AUT to determine the trace information; and

sending the trace information to a security test engine performing the dynamic security analysis test.

17. The method of claim 16 , wherein the trace information includes a stack trace that includes a set of active stack frames of the AUT when the vulnerability occurred, the method further comprising:

classifying, by the security test engine, the vulnerability; and

looking up a possible patch option from a data structure based on the classification.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2016
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 040796/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2016
From: MADOU, MATIAS; SECHMAN, RONALD JOSEPH; SUM, SAM NG MING
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 040382/0229 →
Continuity (1)
Related Publication 20170187743A1 · Jun 29, 2017