Invention Grant
- Patent Title: Determining a source of a vulnerability in software
-
Application No.: US17541945Application Date: 2021-12-03
-
Publication No.: US11921863B2Publication Date: 2024-03-05
- Inventor: Jay Goodman Tamboli , Dustin Summers , Rui Zhang
- Applicant: Capital One Services, LLC
- Applicant Address: US VA McLean
- Assignee: Capital One Services, LLC
- Current Assignee: Capital One Services, LLC
- Current Assignee Address: US VA McLean
- Agency: Sterne, Kessler, Goldstein & Fox P.L.L.C.
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F11/36 ; G06F21/62

Abstract:
Systems and methods are disclosed herein for determining a source of leaked sensitive data (e.g., passwords, insecure coding, log information, any information that should not exist, etc.) in compiled software applications. According to some aspects, a computing device (e.g., a software analysis device, a cloud-computing device, a server, a smart device, binary file/code scanner, etc.) may receive scan pattern information and a binary file of a software application. The computing device may be configured to determine one or more executable files of the software application based on the binary file. Based on the scan pattern information and the one or more executable files, the computing device may determine location information for one or more sensitive data elements configured with the software application. The computing device may use the location information for each of the one or more sensitive data elements to determine a respective source of the sensitive data element.
Public/Granted literature
- US20230177164A1 DETERMINING A SOURCE OF A VULNERABILITY IN SOFTWARE Public/Granted day:2023-06-08
Information query