Distributed security introspection
Abstract
A graph representation of a designated application may be created. The graph representation may include nodes that each represent a computer programming code statement associated with the designated application as well as edges that each represent a logical linkage between two or more computer programming code statements. A determination may be made as to whether the designated application constitutes an unacceptable security risk by comparing the designated graph representation with a plurality of comparison graph representations. When it is determined that the designated application constitutes an unacceptable security risk, a message may be transmitted to prevent the designated application from being executed.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method comprising:
generating a graph representation of an application stored in a storage module in an on-demand database system, the graph representation including a plurality of nodes and a plurality of directional edges connecting the nodes, a first one of the directional edges representing a sequential linkage between first and second computer programming code statements associated with the application; determining via a processor whether the application constitutes a security risk by comparing the graph representation with a plurality of comparison graph representations, one or more of the comparison graph representations representing computer programming code identified as malicious; and when it is determined that the application constitutes a security risk, transmitting a message via a communications interface to prevent the application from being executed within the on-demand database system.
22 . The method recited in claim 21 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more portions not present in one or more of the comparison graph representations.
23 . The method recited in claim 21 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more portions similar to one or more comparison portions in one or more of the comparison graph representations.
24 . The method recited in claim 21 , wherein the on-demand database system provides computing services to a plurality of client organizations via the internet.
25 . The method recited in claim 24 , wherein the application is authored by a first one of the client organizations.
26 . The method recited in claim 25 , wherein the comparison graph representations include a first comparison graph representation representing a first application authored by a second one of the client organizations.
27 . The method recited in claim 21 , wherein the comparison graph representations include a first comparison graph representation representing a prior version of the application.
28 . The method recited in claim 27 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more statements not present in the first comparison graph representation.
29 . The method recited in claim 21 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more nodes corresponding with respective computer programming code statements to transmit information outside the on-demand database system.
30 . The method recited in claim 21 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more nodes corresponding with respective computer programming code statements to update information retrieved from the on-demand database system.
31 . The method recited in claim 21 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more nodes corresponding with respective computer programming code statements to update information stored within the on-demand database system.
32 . The method recited in claim 21 , wherein the application is authored by a third-party software developer within the on-demand database system.
33 . The method recited in claim 21 , wherein the application is configured to access information stored within a multi-tenant database in the on-demand database system, the multi-tenant database storing information associated with a plurality of client organizations.
34 . The method recited in claim 21 , wherein the application is accessible via an application exchange providing applications for purchase and use within the on-demand database system.
35 . A computing system comprising:
a storage medium configurable to store a graph representation of an application in an on-demand database system, the graph representation including a plurality of nodes and a plurality of directional edges connecting the nodes, a first one of the directional edges representing a sequential linkage between first and second computer programming code statements associated with the application; a processor configurable to determine whether the application constitutes a security risk by comparing the graph representation with a plurality of comparison graph representations, one or more of the comparison graph representations representing computer programming code identified as malicious; and a communications interface configurable to transmit a message via a communications interface to prevent the application from being executed within the on-demand database system when it is determined that the application constitutes a security risk.
36 . The system device recited in claim 35 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more nodes corresponding with respective computer programming code statements to transmit information outside the on-demand database system.
37 . The computing system recited in claim 35 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more nodes corresponding with respective computer programming code statements to update information retrieved from the on-demand database system.
38 . The computing system recited in claim 35 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more nodes corresponding with respective computer programming code statements to update information stored within the on-demand database system.
39 . One or more non-transitory computer readable media having instructions stored thereon for performing a method, the method comprising:
generating a graph representation of an application stored in a storage module in an on-demand database system, the graph representation including a plurality of nodes and a plurality of directional edges connecting the nodes, a first one of the directional edges representing a sequential linkage between first and second computer programming code statements associated with the application; determining via a processor whether the application constitutes a security risk by comparing the graph representation with a plurality of comparison graph representations, one or more of the comparison graph representations representing computer programming code identified as malicious; and
when it is determined that the application constitutes a security risk, transmitting a message via a communications interface to prevent the application from being executed within the on-demand database system.
40 . The one or more non-transitory computer readable media recited in claim 39 , wherein determining whether the application constitutes a security risk comprises determining whether the graph representation includes one or more nodes corresponding with respective computer programming code statements to update information stored within the on-demand database system.Join the waitlist — get patent alerts
Track US2022100852A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.