Patents Assigned to SPARROW CO., LTD.
  • Patent number: 11636184
    Abstract: A method for providing a software service of a license management server is disclosed. The method comprises the steps of: receiving a virtual machine interface from a cloud server; installing software of a service provider in the virtual machine interface; transmitting a license to the virtual machine interface; providing ID and password related authority to a user terminal; and providing a service of the software to the user terminal through the virtual machine interface when the user terminal accesses the software. Therefore, source code leakage due to static analysis can be fundamentally prevented.
    Type: Grant
    Filed: September 29, 2021
    Date of Patent: April 25, 2023
    Assignee: SPARROW CO., LTD
    Inventors: Oh Seung Kwon, Won Suk Choi
  • Patent number: 11496502
    Abstract: Disclosed is an operation method for a dynamic analyzer for analyzing an execution state of a web application. The present invention comprises the steps of: analyzing an execution state of the web application on the basis of a final attack string including a parameter which indicates a particular operation to be executed through the web application; and performing an analysis of the execution state of the web application, wherein the final attack string is generated so as to avoid filtering logic which is designed to filter a raw attack string including a predefined parameter. Therefore, the present invention can detect a security vulnerability, which cannot be detected by the existing dynamic analyzer, through easy generation of a final attack string capable of bypassing filtering.
    Type: Grant
    Filed: July 28, 2016
    Date of Patent: November 8, 2022
    Assignee: Sparrow Co., Ltd.
    Inventors: Min Sik Jin, Jong Won Yoon, Jong Hwan Im
  • Publication number: 20220019644
    Abstract: A method for providing a software service of a license management server is disclosed. The method comprises the steps of: receiving a virtual machine interface from a cloud server; installing software of a service provider in the virtual machine interface; transmitting a license to the virtual machine interface; providing ID and password related authority to a user terminal; and providing a service of the software to the user terminal through the virtual machine interface when the user terminal accesses the software. Therefore, source code leakage due to static analysis can be fundamentally prevented.
    Type: Application
    Filed: September 29, 2021
    Publication date: January 20, 2022
    Applicant: SPARROW CO., LTD
    Inventors: Oh Seung KWON, Won Suk CHOI
  • Publication number: 20200167445
    Abstract: A method for providing a software service of a license management server is disclosed. The method comprises the steps of: receiving a virtual machine interface from a cloud server; installing software of a service provider in the virtual machine interface; transmitting a license to the virtual machine interface; providing ID and password related authority to a user terminal; and providing a service of the software to the user terminal through the virtual machine interface when the user terminal accesses the software. Therefore, source code leakage due to static analysis can be fundamentally prevented.
    Type: Application
    Filed: July 28, 2017
    Publication date: May 28, 2020
    Applicant: Sparrow Co., Ltd
    Inventors: Oh Seung KWON, Won Suk CHOI
  • Patent number: 10496516
    Abstract: The present invention relates to a source code analysis device, a computer program for the same, and a recording medium thereof. Disclosed is a source code analysis device including: a source code analysis module including: a syntax analysis unit for extracting and refining information required for analysis; a defect detection unit for detecting defect information; a correction example generation unit for generating correction example information or notice information or both; and an analysis result transmission unit for constructing synthesized analysis result information and transmitting the constructed information to an analysis result output module, and the analysis result output module including: a defect output unit for extracting and outputting the defect information from the synthesized analysis result information, and a correction example output unit for extracting and outputting the correction example information and or notice information or both from the synthesized analysis result information.
    Type: Grant
    Filed: August 26, 2015
    Date of Patent: December 3, 2019
    Assignee: SPARROW CO., LTD.
    Inventors: Hyungkil Ham, Yungbum Jung
  • Publication number: 20190297107
    Abstract: Disclosed is an operation method for a dynamic analyzer for analyzing an execution state of a web application. The present invention comprises the steps of: analyzing an execution state of the web application on the basis of a final attack string including a parameter which indicates a particular operation to be executed through the web application; and performing an analysis of the execution state of the web application, wherein the final attack string is generated so as to avoid filtering logic which is designed to filter a raw attack string including a predefined parameter. Therefore, the present invention can detect a security vulnerability, which cannot be detected by the existing dynamic analyzer, through easy generation of a final attack string capable of bypassing filtering.
    Type: Application
    Filed: July 28, 2016
    Publication date: September 26, 2019
    Applicant: SPARROW CO., LTD
    Inventors: Min Sik JIN, Jong Won YOON, Jong Hwan IM
  • Patent number: 10394687
    Abstract: The present invention relates to a method for classifying alarm types in detecting source code errors, a computer program therefor, and a recording medium thereof. The method for classifying alarm types in detecting source code errors includes: receiving input of alarm path information about an occurring error detection alarm and source code information that is an object associated with the occurring alarm, the alarm path information being information about an execution path related to the error detection; converting the source code into an abstract syntax tree (AST); removing, from the AST, an unnecessary sub-tree that is not related to the error detection alarm; obtaining a feature vector of the AST having the unnecessary sub-tree removed therefrom based on a preset feature pattern set; and classifying, by types, the error detection alarm associated with the feature vector by clustering the obtained feature vector using a preset method.
    Type: Grant
    Filed: November 26, 2015
    Date of Patent: August 27, 2019
    Assignee: SPARROW CO., LTD.
    Inventors: Jongwon Yoon, Minsik Jin
  • Patent number: 10331439
    Abstract: Disclosed is a source code transfer control method, a computer program therefor, and a recording medium therefor. The source code transfer control method is a method executed in a configuration management system interworking with a static analyzer server. The method includes: (a) receiving a source code transfer request; (b) transmitting file identification information on a source code that is requested for transfer, to a static analyzer server; (c) receiving a return value from the static analyzer server on the basis of the file identification information, the return value being produced from an analysis result associated with the transfer-requested source code and loaded on the static analyzer server, the return value being a value produced for each check item that is preset for transfer control; and (d) providing information on whether the transfer-requested source code can be normally transferred on the basis of the return value.
    Type: Grant
    Filed: January 5, 2016
    Date of Patent: June 25, 2019
    Assignee: SPARROW CO., LTD.
    Inventors: Sungjin Kim, Kyeongcheol Kim, Wonsuk Choi, Jongyun Jung