Invention Grant
- Patent Title: Automated security analysis of software libraries
-
Application No.: US14991256Application Date: 2016-01-08
-
Publication No.: US10069855B1Publication Date: 2018-09-04
- Inventor: Jeremy W. Long , Mitch Moon
- Applicant: Wells Fargo Bank, N.A.
- Applicant Address: US CA San Francisco
- Assignee: Wells Fargo Bank, N.A.
- Current Assignee: Wells Fargo Bank, N.A.
- Current Assignee Address: US CA San Francisco
- Agency: Merchant & Gould P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A method for identifying security vulnerabilities in a third party software component includes generating a test application for the third party software component. The test application is generated such that every externally accessible data path in the third party component is called. The test application and the third party software component are analyzed using a static application security testing (SAST) code analyzer. One or more test results are obtained from the SAST code analyzer. The one or more test results are used to identify security vulnerabilities in the third party component.
Information query