Invention Grant
- Patent Title: System and method for application security assessment
- Patent Title (中): 应用安全评估的系统和方法
-
Application No.: US13173218Application Date: 2011-06-30
-
Publication No.: US08695027B2Publication Date: 2014-04-08
- Inventor: Sven Schrecker , Michael Andrews
- Applicant: Sven Schrecker , Michael Andrews
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, Inc.
- Current Assignee: McAfee, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Patent Capital Group
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A system and method in one embodiment includes modules for running a test script to generate a request to a target application, receiving a response from the target application, and running a detector script to inspect the response for a vulnerability. More specific embodiments include a target web site, populating a work in a queue, where the work corresponds to content in the response, and running a second test script or detector script to generate a follow-up request to the application if the vulnerability has been identified in the response. Other embodiments include extracting the work from the queue, and running a second test script corresponding to the extracted work. Other embodiments include storing an injection in an injection cache, de-registering the injection from the injection cache if it is identified in the response, and re-crawling the application, if the injection has not been de-registered from the injection cache.
Public/Granted literature
- US20130247204A1 SYSTEM AND METHOD FOR APPLICATION SECURITY ASSESSMENT Public/Granted day:2013-09-19
Information query