Invention Grant
- Patent Title: Method, system, and storage medium for security of software components
-
Application No.: US16548363Application Date: 2019-08-22
-
Publication No.: US11455400B2Publication Date: 2022-09-27
- Inventor: Brian Fox , Bruce Mayhew , Jason Dillon , Gazi Mahmud
- Applicant: Sonatype, Inc.
- Applicant Address: US MD Fulton
- Assignee: Sonatype, Inc.
- Current Assignee: Sonatype, Inc.
- Current Assignee Address: US MD Fulton
- Agency: Posz Law Group, PLC
- Main IPC: G06F21/54
- IPC: G06F21/54 ; G06F21/56 ; G06F21/57 ; G06F8/71

Abstract:
A computer system for security of components includes at least one processor. For a new version of a component, the processor determines, based on a dataset of release events over time, a historical behavioral analysis of (i) a project that is released with prior versions of the component, and/or (ii) historical committer behavior of a committer that committed the new version of the component, and/or (iii) historical behavior of a publisher of the project. The dataset of release events includes event data collected over time regarding open source project, committers, and repository. The processor determines whether the new version of the component presents an unusual risk profile, based on the historical behavioral analysis. The processor facilitates delayed consumption of the new version of the component in response to determining that the new version of the component presents the unusual risk profile.
Public/Granted literature
- US20210056209A1 METHOD, SYSTEM, AND STORAGE MEDIUM FOR SECURITY OF SOFTWARE COMPONENTS Public/Granted day:2021-02-25
Information query