US2017132414A1PendingUtilityA1
Dynamic Application Security Verification
Est. expiryAug 28, 2033(~7.1 yrs left)· nominal 20-yr term from priority
G06F 21/554G06F 21/53G06F 21/568G06F 21/566H04L 63/14G06Q 30/0601H04L 63/1408H04L 63/12H04W 12/12H04W 12/10H04W 12/128
53
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Disclosed are various embodiments for performing security verifications for dynamic applications. An application is executed and it is determined that the application requests access to dynamically loaded code. In response to determining a security risk associated with the dynamically loaded code, a portion of the dynamically loaded code is modified to eliminate the security risk.
Claims
exact text as granted — not AI-modifiedTherefore, the following is claimed:
1 . A system, comprising:
at least one computing device; and at least one application executable by the at least one computing device, wherein, when executed, the at least one application causes the at least one computing device to at least:
execute an instance of an application in a sandboxed environment;
determine that the instance of the application is requesting access to dynamically loaded code;
determine a security risk associated with the dynamically loaded code; and
modify a portion of the dynamically loaded code to eliminate the security risk, a remaining portion of the dynamically loaded code being unmodified.
2 . The system of claim 1 , wherein modifying a portion of the dynamically loaded code comprises repairing the portion of the dynamically loaded code.
3 . The system of claim 1 , wherein modifying the portion of the dynamically loaded code comprises replacing the portion of the dynamically loaded code with another portion of code.
4 . The system of claim 1 , wherein the application is one of a plurality of applications being offered for at least one of download or sale via an application marketplace.
5 . The system of claim 1 , wherein the security risk is determined based at least in part on at least one of: a version of the dynamically loaded code, a signature of the dynamically loaded code, a source of the dynamically loaded code, a previous security evaluation, a code inspection of the dynamically loaded code.
6 . The system of claim 1 , wherein determining that the application requests accesses the dynamically loaded code further comprises detecting of at least one of: a download of data to executable code memory of the at least one computing device or previously downloaded data including recognizable executable code.
7 . A method, comprising:
executing, via at least one of one or more computing devices, an application in a sandboxed environment; determining, via at least one of the one or more computing devices, that the application is attempting to access dynamically loaded code; and modifying, via at least one of the one or more computing devices, a portion of the dynamically loaded code to repair a detected security risk of the dynamically loaded code, a remaining portion of the dynamically loaded code being unmodified.
8 . The method of claim 7 , wherein the one or more computing devices comprises a client device.
9 . The method of claim 8 , further comprising:
routing, via the client device, the dynamically loaded code to a server device via a proxy service; and receiving, via the client device, an indication of the detected security risk via the server device.
10 . The method of claim 8 , further comprising:
routing, via the client device, a uniform resource locator (URL) corresponding to the dynamically loaded code to a server device via a proxy service; and receiving, via the client device, an indication of the detected security risk via the server device.
11 . The method of claim 7 , further comprising performing, via at least one of the one or more computing devices, a security evaluation of the dynamically loaded code, the detected security risk being detected as a result of the security evaluation.
12 . The method of claim 11 , wherein the security evaluation is based at least in part on a prior security evaluation of the dynamically loaded code.
13 . The method of claim 7 , wherein the application is being offered for at least one of download or sale via an application marketplace, and an offering of the application via the application marketplace includes a flag indicating a potential security risk.
14 . The method of claim 7 , further comprising identifying the security risk based at least in part on at least one of: a version of the dynamically loaded code or a source of the dynamically loaded code.
15 . A system, comprising:
a client device; and a first application executable by the client device, wherein, when executed, the first application causes the client device to at least:
execute a second application;
determine that the second application accesses dynamically loaded code;
determine a security risk associated with the dynamically loaded code in response to an evaluation of the dynamically loaded code; and
reduce the security risk by modifying a portion of the dynamically loaded code, a remaining portion of the dynamically loaded code being unmodified.
16 . The system of claim 15 , wherein the second application is executed in a sandboxed environment.
17 . The system of claim 16 , wherein the sandboxed environment comprises an emulator of the client device.
18 . The system of claim 16 , wherein the sandboxed environment comprises a prevention layer configured to prevent access by the second application to resources of the client device.
19 . The system of claim 15 , wherein determining the security risk further comprises:
transmitting the dynamically loaded code to a computing device over a network, the evaluation being performed by the computing device; and receiving an indication of the security risk from the computing device.
20 . The system of claim 15 , wherein determining that the second application accesses the dynamically loaded code further comprises:
determining that the second application attempts to contact an external network site without using a required application programming interface (API) call.Join the waitlist — get patent alerts
Track US2017132414A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.