Invention Grant
- Patent Title: System and method for identifying vulnerabilities in code due to open source usage
-
Application No.: US15973702Application Date: 2018-05-08
-
Publication No.: US10713364B2Publication Date: 2020-07-14
- Inventor: Aharon Abadi , Doron Cohen , David Habusha , Ron Rymon , Rami Sass
- Applicant: WHITESOURCE LTD.
- Applicant Address: IL
- Assignee: WHITESOURCE LTD.
- Current Assignee: WHITESOURCE LTD.
- Current Assignee Address: IL
- Agency: The Roy Gross Law, LLC
- Agent Roy Gross
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F11/36 ; G06F8/41 ; G06F16/901

Abstract:
A method, computerized apparatus and computer program product, the method comprising: obtaining computer code; determining from the computer code a collection of components reachable from the computer code; providing information about the components to a server; identifying by the server using information retrieved from a database, reachable components associated with the collection of components, which have stored vulnerabilities; determining from the computer code and the reachable components that have stored vulnerabilities, a collection of reachable finer resolution components; identifying, further components from the collection of reachable finer resolution components, which have stored vulnerabilities; and outputting information about the further components, wherein the computer code cannot be reconstructed from the information about the collection of components and the information about the finer resolution components.
Information query