Invention Grant
- Patent Title: Application testing for security vulnerabilities
-
Application No.: US14731473Application Date: 2015-06-05
-
Publication No.: US10380006B2Publication Date: 2019-08-13
- Inventor: Roee Hay , Omer Tripp
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Edward J. Wixted, III
- Main IPC: G06F11/36
- IPC: G06F11/36 ; G06F21/54

Abstract:
In an approach for testing an application for a security vulnerability, a processor inserts an instrumentation hook in the application to be tested, wherein the instrumentation hook is executed prior to a sink operation. A processor transmits a probe input value to the application to be tested. A processor detects a modification to the probe input value at the instrumentation hook by comparing the probe input value at the instrumentation hook to a signature value and detecting that the probe input value matches the signature value. A processor removes the sink operation from testing for the security vulnerability.
Public/Granted literature
- US20160359896A1 APPLICATION TESTING FOR SECURITY VULNERABILITIES Public/Granted day:2016-12-08
Information query