US2015220739A1PendingUtilityA1

Global Variable Security Analysis

Assignee: IBMPriority: Nov 22, 2010Filed: Apr 16, 2015Published: Aug 6, 2015
Est. expiryNov 22, 2030(~4.3 yrs left)· nominal 20-yr term from priority
G06F 2221/034G06F 21/00G06F 21/577
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method includes determining selected global variables in a program for which flow of the selected global variables through the program is to be tracked. The selected global variables are less than all the global variables in the program. The method includes using a static analysis performed on the program, tracking flow through the program for the selected global variables. In response to one or more of the selected global variables being used in security-sensitive operations in the flow, use is analyzed of each one of the selected global variables in a corresponding security-sensitive operation. In response to a determination the use may be a potential security violation, the potential security violation is reported. Apparatus and computer program products are also disclosed.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 determining selected global variables in a program for which flow of the selected global variables through the program is to be tracked, the selected global variables being less than all the global variables in the program; and   using a static analysis performed on the program, tracking flow through the program for the selected global variables; in response to one or more of the selected global variables being used in security-sensitive operations in the flow, analyzing use of each one of the selected global variables in a corresponding security-sensitive operation; and in response to a determination the use may be a potential security violation, reporting the potential security violation.   
     
     
         2 . The method of  claim 1 , wherein reporting comprises placing indicia of the potential security violation into a file. 
     
     
         3 . The method of  claim 1 , wherein reporting further comprises displaying indicia of the potential security violation using a user interface displayed on a display. 
     
     
         4 . The method of  claim 1 , wherein determining the selected global variables in the program for which flow of the selected global variables through the program is to be tracked further comprises using at least one of a name of the selected global variable or a type of the selected global variable to determine that the flow of the selected global variable through the program is to be tracked. 
     
     
         5 . The method of  claim 1 , wherein tracking further comprises tracking flow through the program for the selected global variables by passing the selected global variables in method calls between methods of the program. 
     
     
         6 . The method of  claim 1 , wherein tracking further comprises tracking flow through the program for a given one of the selected global variables by reusing a smile representation of the one global variable for different scopes of the one global variable and resetting analysis data for the global variable prior to analyzing the different scopes. 
     
     
         7 . The method of  claim 1 , wherein a given one of the selected global variables comprises at least one key of a map object and wherein using a static analysis performed on the program further comprises tracking flow through the program for each of the at least one keys; in response to one of the at least one keys being used in a security-sensitive operation in the flow, analyzing use of the one key in the security-sensitive operation; and in response to a determination the use of the one key may be a potential security violation, reporting the potential security violation. 
     
     
         8 . A computer program product, comprising:
 a non-transitory computer readable storage medium having computer readable program code embodied therewith, the computer readable program code comprising:
 code for determining selected global variables in a program for which flow of the selected global variables through the program is to be tracked, the selected global variables being less than all the global variables in the program; and 
 code for, using a static analysis performed on the program, tracking flow through the program for the selected global variables; in response to one or more of the selected global variables being used in security-sensitive operations in the flow, analyzing use of each one of the selected global variables in a corresponding security-sensitive operation; and in response to a determination the use may be a potential security violation, reporting the potential security violation. 
   
     
     
         9 . The computer program product of  claim 8 , wherein reporting comprises placing indicia of the potential security violation into a file. 
     
     
         10 . The computer program product of  claim 8 , wherein reporting further comprises displaying indicia of the potential security violation using a user interface displayed on a display. 
     
     
         11 . The computer program product of  claim 8 , wherein determining the selected global variables in the program for which flow of the selected global variables through the program is to be tracked further comprises using at least one of a name of the selected global variable or a type of the selected global variable to determine that the flow of the selected global variable through the program is to be tracked. 
     
     
         12 . The computer program product of  claim 8 , wherein tracking further comprises tracking flow through the program for the selected global variables by passing the selected global variables in computer program product calls between methods of the program. 
     
     
         13 . The computer program product Of  claim 8 , wherein a given one of the selected global variables comprises at least one key of a map object and wherein using a static analysis performed on the program further comprises tracking flow through the program for each of the at least one keys; in response to one of the at least one keys being used in a security-sensitive operation in the flow, analyzing use of the one key in the security-sensitive operation; and in response to a determination the use of the one key may be a potential security violation, reporting the potential security violation. 
     
     
         14 . An apparatus, comprising:
 at least one memory comprising computer code; and   at least one processor,   the computer code controlling the at least one processor to perform at least the following:
 determining selected global variables in a program for which flow of the selected global variables through the program is to be tracked, the selected global variables being less than all the global variables in the program; and 
 using a static analysis performed on the program, tracking flow through the program for the selected global variables; in response to one or more of the selected global variables being used in security-sensitive operations in the flow, analyzing use of each one of the selected global variables in a corresponding security-sensitive operation; and in response to a determination the use may be a potential security violation, reporting the potential security violation. 
   
     
     
         15 . The apparatus of  claim 14 , wherein reporting comprises placing indicia of the potential security violation into a file. 
     
     
         16 . The apparatus of  claim 14 , wherein the apparatus further comprises a display interface coupled to the at least one processor and a display, and wherein reporting further comprises displaying indicia of the potential security violation using a user interface displayed on the display. 
     
     
         17 . The apparatus of  claim 14 , wherein determining the selected global variables in the program for which flow of the selected global variables through the program is to be tracked further comprises using at least one of a name of the selected global variable or a type of the selected global variable to determine that the flow of the selected global variable through the program is to be tracked. 
     
     
         18 . The apparatus of  claim 14 , wherein tracking further comprises tracking flow through the program for the selected global variables by passing the selected global variables in apparatus calls between methods of the program. 
     
     
         19 . The apparatus of  claim 14 , wherein a given one of the selected global variables comprises at least one key of a map object and wherein using a static analysis performed on the program further comprises tracking flow through the program for each of the at least one keys; in response to one of the at least one keys being used in a security-sensitive operation in the flow, analyzing use of the one key in the security-sensitive operation; and in response to a determination the use of the one key may be a potential security violation, reporting the potential security violation.

Join the waitlist — get patent alerts

Track US2015220739A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.