Invention Grant
- Patent Title: Detection of malicious software packages
-
Application No.: US15729304Application Date: 2017-10-10
-
Publication No.: US10055576B2Publication Date: 2018-08-21
- Inventor: Steve Bradford Milner , James Robert Bowes
- Applicant: Red Hat, Inc.
- Applicant Address: US NC Raleigh
- Assignee: Red Hat, Inc.
- Current Assignee: Red Hat, Inc.
- Current Assignee Address: US NC Raleigh
- Agency: Lowenstein Sandler LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/51 ; G06F21/56

Abstract:
Systems and methods for a security tool that verifies the security of a software package. An example method may involve identifying a plurality of components contained in a software package comprising one of a JAR file, an Android application package, a docker image, a container file, or a virtual machine image; comparing the components contained in the software package to a list of known components; classifying the software package as insecure when at least one of the components matches an insecure component, or as secure when each of the compared components matches a corresponding secure component on the list of known components; preventing addition of the software package to a software repository when the software package is classified as insecure; and when insecure, providing an interface to enable a user to request the components of the software package be added as a secure component on the list of known components.
Public/Granted literature
- US20180032720A1 DETECTION OF MALICIOUS SOFTWARE PACKAGES Public/Granted day:2018-02-01
Information query