Invention Grant
- Patent Title: HTTP log integration to web application testing
-
Application No.: US16580057Application Date: 2019-09-24
-
Publication No.: US11297091B2Publication Date: 2022-04-05
- Inventor: Peggy J. Qualls , Travis Hoyt , Cary Hooper
- Applicant: Bank of America Corporation
- Applicant Address: US NC Charlotte
- Assignee: Bank of America Corporation
- Current Assignee: Bank of America Corporation
- Current Assignee Address: US NC Charlotte
- Agency: Weiss & Arons LLP
- Main IPC: H04L65/00
- IPC: H04L65/00 ; H04L29/06 ; G06F11/36 ; G06F16/955

Abstract:
A method for securely testing a web application is provided. The method may include analyzing each HTTP log entry that may be included in a centralized web server log file of a web application. Each HTTP log entry may include an endpoint. The endpoint may be a URL path correlating to a location on the web application. Based on the analysis, the method may include identifying each endpoint included in the web application and generating a first web application site-map based on each identified endpoint. The method may further include determining one or more endpoints on the first web application site map, that may be absent from a second web application site map. The second web application site map may include each crawled endpoint within the web application identified via a crawling of the web application by a web application attack tool for identifying security vulnerabilities.
Public/Granted literature
- US20210092144A1 HTTP LOG INTEGRATION TO WEB APPLICATION TESTING Public/Granted day:2021-03-25
Information query