Invention Grant
- Patent Title: Value based information tracking for security enforcement
-
Application No.: US16128780Application Date: 2018-09-12
-
Publication No.: US11244057B2Publication Date: 2022-02-08
- Inventor: Marco Pistoia , Omer Tripp , Pietro Ferrara , Petar Tsankov
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Scully, Scott, Murphy & Presser, PC
- Agent Daniel P. Morris, Esq.
- Main IPC: G06F21/60
- IPC: G06F21/60 ; G06F21/57 ; G06F9/54 ; G06F21/55

Abstract:
An apparatus, method and computer program product for repairing security vulnerabilities of an application running on a mobile device. The method comprises: monitoring, by a hardware processor running a mobile device application, an application program interface (API) request associated with a data access operation, the data access operation associated with a security vulnerability. The method determines one or more private values provided by the data access operation and tracks, for each determined private value, a use of the private value by the mobile device application. Further, the method determines from the tracked usage, whether a private value has been transformed in a manner associated with the security vulnerability. For each private value that has been transformed, using the processor to modify the private value deemed a security vulnerability prior to an access by the mobile device application.
Public/Granted literature
- US20200082096A1 VALUE BASED INFORMATION TRACKING FOR SECURITY ENFORCEMENT Public/Granted day:2020-03-12
Information query