Invention Grant
- Patent Title: Method and system for data flow monitoring to identify application security vulnerabilities and to detect and prevent attacks
-
Application No.: US17481737Application Date: 2021-09-22
-
Publication No.: US11886599B2Publication Date: 2024-01-30
- Inventor: Andreas Berger , Christian Schwarzbauer
- Applicant: Dynatrace LLC
- Applicant Address: US MA Waltham
- Assignee: Dynatrace LLC
- Current Assignee: Dynatrace LLC
- Current Assignee Address: US MA Waltham
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F21/55 ; G06F21/56

Abstract:
A technology to identify processing paths of untrusted input data received by applications that are vulnerable to attacks and to further detect and prevent actual attacks that try to exploit those vulnerabilities is disclosed. Application code is augmented at run-time with sensor code which detects the entry of input-data into the application and further traces the propagation, manipulation and, sanitization of this input-data until its usage in a data sink. The so generated data-flow traces reveal data-flow paths that lack required sanitization measures to neutralize potentially harmful input-data. Such data-flow paths are reported as vulnerabilities. Further, input-data that reaches data-sink interfaces is scanned by data-sink sensors to identify harmful input data. On identification of harmful input data, an attack is reported, and countermeasures are applied to prevent the identified attack.
Public/Granted literature
Information query