The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 19, 2026

Filed:

Jul. 31, 2018
Applicant:

Veracode, Inc., Burlington, MA (US);

Inventors:

Darius Tsien Wei Foo, Singapore, SG;

Ming Yi Ang, Singapore, SG;

Jie Shun Yeo, Singapore, SG;

Asankhaya Sharma, Singapore, SG;

Assignee:

Veracode, Inc., Burlington, MA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 8/77 (2018.01); G06F 16/901 (2019.01); G06F 16/903 (2019.01); G06F 21/57 (2013.01);
U.S. Cl.
CPC ...
G06F 21/577 (2013.01); G06F 8/77 (2013.01); G06F 16/9024 (2019.01); G06F 16/90335 (2019.01); G06F 2221/033 (2013.01);
Abstract

To analyze open-source code at a large scale, a security domain graph language ('SGL') has been created that functions as a vulnerability description language and facilitates program analysis queries. The SGL facilitates building and maintaining a graph database to catalogue vulnerabilities found in open-source components. This vulnerability database generated with SGL is used for analysis of software projects which use open source components. An agent which interacts with the vulnerability database can perform a scan of a software project to identify open-source components used in the project and submit queries to the vulnerability database to identify vulnerabilities which may affect the open-source components in the project. Results of the scan are presented to a user in the form of a vulnerability report which indicates vulnerabilities that have been discovered and which open-source components the vulnerabilities affect.


Find Patent Forward Citations

Loading…