Invention Grant
- Patent Title: Mechanism to detect and analyze SQL injection threats
-
Application No.: US11082280Application Date: 2005-03-16
-
Publication No.: US07752177B2Publication Date: 2010-07-06
- Inventor: Dmitri Bronnikov , Charles Wetherell
- Applicant: Dmitri Bronnikov , Charles Wetherell
- Applicant Address: US CA Redwood Shores
- Assignee: Oracle International Corporation
- Current Assignee: Oracle International Corporation
- Current Assignee Address: US CA Redwood Shores
- Agency: Hickman Palermo Truong & Becker LLP
- Main IPC: G06F7/00
- IPC: G06F7/00

Abstract:
A vulnerability analysis tool is provided for identifying SQL injection threats. The tool is able to take advantage of the fact that the code for many database applications is located in modules stored within a database. The tool constructs a data flow graph based on all, or a specified subset, of the application code within the database. The tool identifies, within the data flow graph, the nodes that represent values used to construct SQL commands. Paths to those nodes are analyzed to determine whether any SQL injection threats exist.
Public/Granted literature
- US07860842B2 Mechanism to detect and analyze SQL injection threats Public/Granted day:2010-12-28
Information query