Patent · US Active

Generating sound and minimal security reports based on static analysis of a program

US8850405B2 · kind B2 · utility

7Cited by
2References
21Claims
0Family size

Assignee

Inventors

Key dates

Filing dateFeb 23, 2011
Grant dateSep 30, 2014
Priority date
Expiry dateNov 19, 2032

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F8/77
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

A method is disclosed that includes, using a static analysis, analyzing a software program to determine a number of paths from sources accepting information to sinks using that information or a modified version of that information and to determine multiple paths from the number of paths. The determined multiple paths have a same transition from an application portion of the software program to a library portion of the software program and require a same downgrading action to address a vulnerability associated with source-sink pairs in the multiple paths. The analyzing includes determining the multiple paths using a path-sensitive analysis. The method includes, for the determined multiple paths, grouping the determined multiple paths into a single representative indication of the determined multiple paths. The method includes outputting the single representative indication. Computer program products and apparatus are also disclosed.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.