Invention Grant
- Patent Title: Command injection identification
-
Application No.: US17850427Application Date: 2022-06-27
-
Publication No.: US11714899B2Publication Date: 2023-08-01
- Inventor: Asaf Karas , Or Peles , Meir Tsvi , Anton Nayshtut
- Applicant: JFROG LTD.
- Applicant Address: IL Netanya
- Assignee: JFROG LTD
- Current Assignee: JFROG LTD
- Current Assignee Address: IL Netanya
- Agency: Myers Wolin, LLC
- Main IPC: G06F21/54
- IPC: G06F21/54 ; H04L9/40 ; G06F21/55

Abstract:
A method, system and product for command injection identification. An input hook function is configured to be executed in response to a potential input provisioning event. The input hook function is configured to perform: analyzing a potential input of the potential input provisioning event to identify whether the potential input comprises a command separator and an executable product; and in response to identifying the command separator and the executable product, recording a suspicious input event indicating the command separator and the executable product. An execution hook function is configured to be executed in response to a potential execution event. The execution hook function is configured to perform: in response to a determination that an execution command of the potential execution event comprises the command separator and the executable product of the suspicious input event, flagging the execution command as a command injection attack.
Public/Granted literature
- US20220335122A1 COMMAND INJECTION IDENTIFICATION Public/Granted day:2022-10-20
Information query