After-the-Fact Configuration of Static Analysis Tools Able to Reduce User Burden
Abstract
A method includes mapping, based on a first mapping from possible security findings to possible configuration-related sources of imprecision, actual security findings from a static analysis of a program to corresponding configuration-related sources of imprecision, the mapping of the actual security findings creating a second mapping. A user is requested to configure selected ones of the configuration-related sources of imprecision from the second mapping. Responsive to a user updating configuration corresponding to the selected ones of the configuration-related sources of imprecision, security analysis results are updated for the static analysis of the program at least by determining whether one or more security findings from the security analysis results are no longer considered to be vulnerable based on the updated configuration by the user. The updated security analysis results are output. Apparatus and program products are also disclosed.
Claims
exact text as granted — not AI-modified1 . A method, comprising:
mapping, based on a first mapping from possible security findings to possible configuration-related sources of imprecision, actual security findings from a static analysis of a program to corresponding configuration-related sources of imprecision, the mapping of the actual security findings creating a second mapping; requesting a user configure selected ones of the configuration related sources of imprecision from the second mapping; responsive to a user updating configuration corresponding to the selected ones of the configuration-related sources of imprecision, updating security analysis results for the static analysis of the program at least determining whether one or more security findings from the security analysis results are no longer considered to be vulnerable based on the updated configuration by the user; and outputting the updated security analysis results.
2 . The method of claim 1 , wherein updating security analysis results further comprises:
responsive to a determination one or more security findings from the security analysis results are no longer considered to be vulnerable based on the updated configuration by the user, removing the determined one or more security findings from the security analysis results.
3 . The method of claim , wherein outputting further comprises outputting the updated security analysis results to a display.
4 . The method of claim 1 , further comprising, prior to requesting, selecting the selected ones of the configuration-related sources of imprecision.
5 . The method of claim 4 , wherein selecting further comprises converging on a subset of the configuration-related sources of imprecision that optimizes the following two constraints:
minimum number of configuration-related sources of imprecision; and maximal precision, and setting the subset of the configuration-related sources of imprecision as the selected configuration-related sources of imprecision.
6 . The method of claim 4 , wherein selecting further comprises requesting the user to specify configuration-related sources of imprecision and setting the specified configuration-related sources of imprecision as the selected configuration-related sources of imprecision.
7 . The method of claim 4 , wherein selecting further comprises requesting the user specify a number of configuration-related sources of imprecision that cover at least a certain percentage of the total number of configuration-related sources of imprecision and setting the specified configuration-related sources of imprecision as the selected configuration-related sources of in precision.
8 . The method of claim 1 , wherein requesting further comprises outputting indications requesting the user configure the selected configuration-related sources of imprecision.
9 . The method of claim 1 , wherein:
the method further comprises, prior to mapping actual security findings from a static analysis of the program to corresponding configuration-related sources of imprecision, performing a first static analysis to determine the actual security findings; and determining whether one or more security findings from the security analysis results are no longer considered to be vulnerable based on the updated configuration by the user further comprises performing a second static analysis on the program specifically on flows affected by the configuration updated by the user.
10 . The method of claim 1 , wherein:
the method further comprises, prior to mapping actual security findings from is static analysis of the program to corresponding configuration-related sources of imprecision, performing a first static analysis to determine the actual security findings and to compute metadata for reported vulnerabilities; and determining whether one or more security findings from the security analysis results are no longer considered to be vulnerable based on the updated configuration by the user further comprises examining the computed metadata to determine whether one or more security findings from the security analysis results are no longer considered to be vulnerable.
11 - 20 . (canceled)Join the waitlist — get patent alerts
Track US2014373157A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.