System and method for identifying software changes
Abstract
One embodiment includes an enterprise trust server (ETS) programmed to execute machine readable instructions. The ETS includes a user interface configured to initiate generation of a first file signature associated with a first file accessed from a file system associated with a computer system at a first time and generation of a second file signature associated with a second file accessed from the file system at a second time subsequent to the first time. The ETS also includes a file signature comparator configured to compare the first and second file signatures to determine a difference set of file signatures. The ETS can be configured to send a request comprising the difference set of file signatures to a trust repository and to receive a response that identifies a software product associated with the first and second files that changed between the first and second times based on the difference set of file signatures.
Claims
exact text as granted — not AI-modified1 . A system comprising a processor and memory and programmed to execute machine readable instructions that, when executed, cause the system to:
initiate:
generation of a first at least one file signature associated with a first at least one file accessed from at least one file system associated with a computer system at a first time, and
generation of a second at least one file signature associated with a second at least one file accessed from the at least one file system at a second time subsequent to the first time; and
based on a comparison of the first and second at least one file signature identify at least one software product associated with the first and second at least one file that changed between the first and second times.
2 . The system of claim 1 , wherein the comparison comprises at least one file signature that is not in the second at least one file signature, at least one file signature in the second at least one file signature that is not in the first at least one file signature, at least one file signature in each of the first and second at least one file signatures having at least one common characteristic and at least one difference in file content, or an indication of no difference between the first and second at least one file signature.
3 . The system of claim 1 , wherein the first and second at least one file signatures comprise cryptographic hash data associated with at least a portion of file content of the respective first and second at least one file based on a non-reversible data encoding algorithm that identifies the at least a portion of the file content of the respective first and second at least one file, the trust repository being configured to compare the cryptographic hash data with predetermined cryptographic hash data associated with a plurality of software products to determine the at least one software product that changed.
4 . The system of claim 1 , wherein the machine readable instructions cause the system to generate a software change report comprising a list of potential software products that changed.
5 . The system of claim 1 , wherein the machine readable instructions cause the system to implement a matching algorithm on the difference to generate matching scores corresponding to likelihoods that respective software products correspond to the at least one software product.
6 . The system of claim 1 , wherein the machine readable instructions cause the system to:
initiate generation of the first and second at least one file signatures in response to at least one scan request that is received via a user interface; and scan the at least one file system to generate the first and second at least one file signatures at the respective first and second times.
7 . The system of claim 1 , wherein the machine readable instructions cause the system to identify at least one potential cause for a respective change associated with the first and second at least one file between the first and second times based on the patterns associated with changes in difference sets of file signatures.
8 . The system of claim 1 , wherein the machine readable instructions cause the system to store the first at least one file signature at approximately the first time as a baseline set of file signatures for comparison with the second at least one file signature at the second time, and wherein the second at least one file signature is saved at approximately the second time for comparison with a third at least one file signature generated at a third time, the third at least one file signature being associated with a third at least one file accessed from the at least one file system at the third time.
9 . The system of claim 8 , wherein the third at least one file accessed from the at least one file system at the third time is associated with a user specified at least one software product in response to a determination that the difference set of file signatures at the second time is associated with the user specified at least one software product.
10 . The system of claim 8 , wherein the system comprises one or more enterprise trust servers and a trust repository communicatively coupled to the enterprise trust servers via a network, and wherein the trust repository is configured to periodically access software resources from a plurality of resource locations on the network to generate predetermined software file signature data.
11 . A non-transitory computer-readable medium comprising instructions for identifying a change in software on a computer system, the medium comprising instructions for:
scanning at least one file system associated with the computer system to access at least one file in response to a software change identification request; generating at least one file signature corresponding to the respective at least one file; comparing the at least one file signature to at least one baseline file signature corresponding to a state of the at least one file at a previous time; requesting identification of at least one software product associated with the at least one file that changed since the previous time based on the comparing; and receiving an indication of the at least one software product determined based on predetermined file signature data associated with a plurality of software products.
12 . The non-transitory computer-readable medium of claim 11 , further comprising instructions for generating a difference set of file signatures based on the comparing, the difference set of file signatures comprising at least one file signature in the at least one baseline file signature that is not in the generated at least one file signature, at least one file signature in the generated at least one file signature that is not in the at least one baseline file signature, at least one file signature in each of the baseline and generated at least one file signature having at least one common characteristic and at least one difference in file content, or an indication of no difference between the first baseline and generated at least one file signature.
13 . The non-transitory computer-readable medium of claim 12 , further comprising instructions for generating a software change report comprising identification of the at least one software product associated with the at least one file signature in the at least one baseline file signature that is not in the generated at least one file signature, with the at least one file signature in the generated at least one file signature that is not in the at least one baseline file signature, or with the at least one file signature in each of the baseline and generated at least one file signature having at least one common characteristic and at least one difference in file content.
14 . The non-transitory computer-readable medium of claim 12 , wherein generating the at least one file signature comprises generating cryptographic hash data associated with at least a portion of file content of the at least one file based on a non-reversible data encoding algorithm that identifies the at least one file, further comprising instructions for comparing the difference set of file signatures by comparing the cryptographic hash data of the difference set of file signatures with predetermined cryptographic hash data associated with the plurality of software products to determine the at least one software product that changed since the previous time.
15 . The non-transitory computer-readable medium of claim 13 , wherein the indication is determined according to a matching algorithm of the difference set of file signatures with respect to the predetermined file signature data to generate matching scores corresponding to likelihoods that respective software products correspond to the at least one software product, and wherein the software change report comprises a list of a plurality of potential software products corresponding to the at least one software product and the matching scores associated with the respective plurality of potential software products.
16 . The non-transitory computer-readable medium of claim 13 , wherein the difference set of file signatures is a first difference set of file signatures and wherein the software change report is a first software change report, the medium further comprising instructions for:
storing the at least one file signature as the at least one baseline file signature at a first time; initiating a second software change identification request at a second time subsequent to the first time; scanning the at least one file system associated with the computer system to access a second at least one file in response to the second software change identification request; generating a second at least one file signature corresponding to the respective second at least one file; comparing the second at least one file signature to the at least one baseline file signature to generate a second difference set of file signatures; receiving results corresponding to a comparison of the second difference set of file signatures with the predetermined file signature data to determine the at least one software product associated with the second at least one file that changed since the first time; and generating a second software change report associated with the determination of the at least one software product that changed based on the results corresponding to the comparison of the second difference set of file signatures with the predetermined file signature data.
17 . The non-transitory computer-readable medium of claim 11 , wherein the indication further comprises at least one potential cause for the change in the at least one software product based on a comparison of characteristics of the change in the at least one software product with predetermined software change pattern data.
18 . A network system comprising:
a plurality of enterprise trust servers comprising a processor and memory and programmed with machine-readable instructions that when executed cause the enterprise trust servers to:
initiate generation of a first plurality of file signatures associated with a first plurality of files accessed from at least one file system associated with at least one computer system at a first time;
initiate generation of a second plurality of file signatures associated with a second plurality of files accessed from the at least one file system at a second time subsequent to the first time;
compare the respective first and second pluralities of file signatures to determine a difference set of file signatures; and
a computer programmed to:
receive the difference set of file signatures from the plurality of enterprise trust servers;
compare the difference set of file signatures with predetermined file signature data associated with a plurality of software products to determine at least one software product associated with the first and second pluralities of files that changed between the first and second times; and
send results associated with the comparison back to the respective plurality of enterprise trust servers.
19 . The system of claim 18 , wherein the first and second pluralities of file signatures comprise cryptographic hash data associated with file content of the respective first and second pluralities of files based on a non-reversible data encoding algorithm that identifies the respective first and second pluralities of files, the trust repository being configured to compare the cryptographic hash data of the difference set of file signatures with predetermined cryptographic hash data associated with the plurality of software products to determine the at least one software product associated with the first and second pluralities of files that changed between the first and second times.
20 . The system of claim 18 , wherein the computer comprises a software change storage configured to store patterns associated with changes in difference sets of file signatures, the computer being further programmed to identify at least one potential cause for a respective change associated with the first and second pluralities of files between the first and second times.
21 . The system of claim 18 , wherein the computer is programmed to periodically access software resources from a plurality of web sites on the network to generate the predetermined file signature data.Join the waitlist — get patent alerts
Track US2016134422A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.