Invention Grant
- Patent Title: Persistent cross-site scripting vulnerability detection
-
Application No.: US15914679Application Date: 2018-03-07
-
Publication No.: US10264011B2Publication Date: 2019-04-16
- Inventor: Emanuel Bronshtein , Roee Hay , Sagi Kedmi
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Nathan M. Rau
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Various techniques for detecting a persistent cross-site scripting vulnerability are described herein. In one example, a method includes detecting, via the processor, a read operation executed on a resource using an instrumentation mechanism and returning, via the processor, a malicious script in response to the read operation. The method also includes detecting, via the processor, a write operation executed on the resource using the instrumentation mechanism and detecting, via the processor, a script operation executed by the malicious script that results in resource data being sent to an external computing device from a client device. Furthermore, the method includes receiving, via the processor, metadata indicating the execution of the read operation, the write operation, and the script operation.
Public/Granted literature
- US20180198817A1 PERSISTENT CROSS-SITE SCRIPTING VULNERABILITY DETECTION Public/Granted day:2018-07-12
Information query