Invention Grant
- Patent Title: Detecting security vulnerabilities in web applications
- Patent Title (中): 检测Web应用程序中的安全漏洞
-
Application No.: US13174628Application Date: 2011-06-30
-
Publication No.: US08695098B2Publication Date: 2014-04-08
- Inventor: Marco Pistoia , Ori Segal , Omer Tripp
- Applicant: Marco Pistoia , Ori Segal , Omer Tripp
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: North Shore Patents, P.C.
- Agent Michele Liu Baillie
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
Method to detect security vulnerabilities includes: interacting with a web application during its execution to identify a web page exposed by the web application; statically analyzing the web page to identify a parameter within the web page that is constrained by a client-side validation measure and that is to be sent to the web application; determining a server-side validation measure to be applied to the parameter in view of the constraint placed upon the parameter by the client-side validation measure; statically analyzing the web application to identify a location within the web application where the parameter is input into the web application; determining whether the parameter is constrained by the server-side validation measure prior to the parameter being used in a security-sensitive operation; and identifying the parameter as a security vulnerability.
Public/Granted literature
- US20130007886A1 DETECTING SECURITY VULNERABILITIES IN WEB APPLICATIONS Public/Granted day:2013-01-03
Information query