Invention Grant
- Patent Title: Method, system, and computer program product for automatically mitigating vulnerabilities in source code
-
Application No.: US14845281Application Date: 2015-09-04
-
Publication No.: US09639703B2Publication Date: 2017-05-02
- Inventor: Jim Liu
- Applicant: Lucent Sky Corporation
- Applicant Address: US CA Pasadena
- Assignee: Lucent Sky Corporation
- Current Assignee: Lucent Sky Corporation
- Current Assignee Address: US CA Pasadena
- Agency: Jianq Chyun IP Office
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F9/45 ; G06F21/53

Abstract:
A method for automatically mitigating vulnerabilities in a source code of an application is provided in the present invention. The method includes the following steps. First, the source code is complied, and a path graph is built according to the compiled source code. The path graph includes a plurality of paths traversing from sources to sinks, and each of the paths includes a plurality of nodes. Then, at least one tainted path is identified by enabling a plurality of vulnerability rules. Each of the at least one tainted path corresponds to a vulnerability, and each of the at least one vulnerability corresponds to a sanitization method. Then, the at least one vulnerability is determined if it is mitigable. If the at least one vulnerability is mitigable, the at least one vulnerability is mitigated automatically. Furthermore, the method may be implemented as a system and a computer program product.
Public/Granted literature
- US20150379272A1 METHOD, SYSTEM, AND COMPUTER PROGRAM PRODUCT FOR AUTOMATICALLY MITIGATING VULNERABILITIES IN SOURCE CODE Public/Granted day:2015-12-31
Information query