- Patent Title: System and method for identifying unpermitted data in source code
-
Application No.: US17065324Application Date: 2020-10-07
-
Publication No.: US11610000B2Publication Date: 2023-03-21
- Inventor: Jack Lawson Bishop, III , Jason Conrad Starin , Kevin Dean Kirkwood
- Applicant: Bank of America Corporation
- Applicant Address: US NC Charlotte
- Assignee: Bank of America Corporation
- Current Assignee: Bank of America Corporation
- Current Assignee Address: US NC Charlotte
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F21/56 ; G06F16/245 ; G06F8/75

Abstract:
A system configured for identifying unpermitted data in source code receives a search query comprising particular keywords related to the unpermitted data. The system labels the source code with vulnerability factors and categories of those vulnerability factors, where the vulnerability factors indicate a security vulnerability and the categories provide information about the security vulnerability of the source code. The system performs a static analysis on the source code to identify instances of the particular keyword in a data flow and control flow of the source code. The system performs a vulnerability analysis on the source code to determine a vulnerability level of the source code, in which factor weights and category weights for each code portion of the source code are determined. The system calculates a weighted sum of the factor weights and category weights for each code portion, thereby detecting instances of unpermitted data in source code.
Public/Granted literature
- US20220108022A1 SYSTEM AND METHOD FOR IDENTIFYING UNPERMITTED DATA IN SOURCE CODE Public/Granted day:2022-04-07
Information query