Managing security of source code

US10089463B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-10089463-B1
Application numberUS-201213626240-A
CountryUS
Kind codeB1
Filing dateSep 25, 2012
Priority dateSep 25, 2012
Publication dateOct 2, 2018
Grant dateOct 2, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method is used in managing security of source code. Source code characteristics are derived from a source code change. Based on the source code characteristics, risk information associated with the source code change is produced.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method for use in managing security of source code, the computer-implemented method comprising: receiving, from a user, an electronic request to submit a source code change; performing an analysis of one or more prior source code changes associated with the user to determine the user's typical halstead complexity measure, typical cyclomatic complexity measure, typical afferent coupling measure, and typical efferent coupling measure, wherein said halstead measure describes a coding style of the user and is derived from a number of distinct operators, a number of distinct operands, a total number of operators, and a total number of operands in connection with the one or more prior source code changes, wherein the cyclomatic complexity measure relates to a number of linearly independent paths through a unit of a project, and wherein the afferent and efferent coupling measures relate respectively to a number of other classes that reference a class and a number of other classes referenced by a class; determining a riskiness in connection with the received source code change by measuring a deviation in the received source code change from the said measures, wherein the riskiness indicates whether the user is genuine or fraudulent; and based on the riskiness in connection with the received source code change, controlling submission of the source code change to a source code repository such that the source code change will be submitted if the riskiness indicates that the user is genuine and will be rejected if the riskiness indicates that the user is fraudulent. 2. The method of claim 1 , wherein the source code change originates from a developer workstation and is submitted to a source code repository. 3. The method of claim 1 , wherein the riskiness is used to help provide an intrusion-resilient source code repository. 4. The method of claim 1 , wherein determining the riskiness is based on profiling a user's coding style based on textual clues. 5. The method of claim 1 , wherein determining the riskiness is based on measuring the deviation in the change from a user's normal coding style. 6. The method of claim 1 , wherein determining the riskiness is based on measuring the deviation in the change from file types that a user typically edits. 7. The method of claim 1 , wherein determining the riskiness is based on measuring the deviation in the change from a user's typical comment style. 8. The method of claim 1 , wherein determining the riskiness is based on measuring the deviation in the change from a user's typical writing errors. 9. The method of claim 1 , wherein determining the riskiness is based on measuring the deviation in the change from a user's typical naming conventions. 10. A system for use in managing security of source code, the system comprising: memory; and processing circuitry coupled to the memory, the memory storing instructions which, when executed by the processing circuitry, cause the processing circuitry to: receive, from a user, an electronic request to submit a source code change; perform an analysis of one or more prior source code changes associated with the user to determine the user's typical halstead complexity measure, typical cyclomatic complexity measure, typical afferent coupling measure, and typical efferent coupling measure, wherein said halstead measure describes a coding style of the user and is derived from a number of distinct operators, a number of distinct operands, a total number of operators, and a total number of operands in connection with the one or more prior source code changes, wherein the cyclomatic complexity measure relates to a number of linearly independent paths through a unit of a project, and wherein the afferent and efferent coupling measures relate respectively to a number of other classes that reference a class and a number of other classes referenced by a class; determine a riskiness in connection with the received source code change by measuring a deviation in the received source code change from the said measures, wherein the riskiness indicates whether the user is genuine or fraudulent; and based on the riskiness in connection with the received source code change, control submission of the source code change to a source code repository such that the source code change will be submitted if the riskiness indicates that the user is genuine and will be rejected if the riskiness indicates that the user is fraudulent. 11. The system of claim 10 , wherein the source code change originates from a developer workstation and is submitted to a source code repository. 12. The system of claim 10 , wherein the riskiness is used to help provide an intrusion-resilient source code repository.

Assignees

Inventors

Classifications

  • Protecting data · CPC title

  • by manipulating the program code, e.g. source code, compiled code, interpreted code, machine code · CPC title

  • Electricity · mapped topic

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10089463B1 cover?
A method is used in managing security of source code. Source code characteristics are derived from a source code change. Based on the source code characteristics, risk information associated with the source code change is produced.
Who is the assignee on this patent?
Katz Aaron T, Bailey Daniel V, Amar Yavir, and 1 more
What technology area does this patent fall under?
Primary CPC classification G06F21/563. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Oct 02 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).