- Patent Title: Static program analysis in an object-relational mapping framework
-
Application No.: US15500532Application Date: 2014-08-29
-
Publication No.: US10331894B2Publication Date: 2019-06-25
- Inventor: Alvaro Munoz , Yekaterina Tsipenyuk O'Neil
- Applicant: ENTIT SOFTWARE LLC
- Applicant Address: US CA Sunnyvale
- Assignee: ENTIT SOFTWARE LLC
- Current Assignee: ENTIT SOFTWARE LLC
- Current Assignee Address: US CA Sunnyvale
- International Application: PCT/US2014/053444 WO 20140829
- International Announcement: WO2016/032516 WO 20160303
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/57 ; G06F8/75 ; G06F11/36 ; G06F16/28

Abstract:
Example implementations relate to static program analysis. For example, an apparatus includes a processor to perform static program analysis on a set of processor executable instructions associated with an object-relational mapping (ORM) framework. The first set of processor executable instructions includes an object. The processor is also to generate a propagation path of the object based on an execution flow of the object. The propagation path includes a first node and a second node. The first node corresponds to a first ORM operation to store the object in a database. The second node corresponds to a second ORM operation to retrieve the object from the database. The second node is linked to the first node based on a common attribute of the object. In response to a determination that the propagation path includes a sink, the processor is to output a security risk warning.
Public/Granted literature
- US20170220807A1 STATIC PROGRAM ANALYSIS IN AN OBJECT-RELATIONAL MAPPING FRAMEWORK Public/Granted day:2017-08-03
Information query