Invention Grant
- Patent Title: Detecting security vulnerabilities relating to cryptographically-sensitive information carriers when testing computer software
- Patent Title (中): 在测试计算机软件时检测与加密敏感信息载体相关的安全漏洞
-
Application No.: US12564288Application Date: 2009-09-22
-
Publication No.: US08397300B2Publication Date: 2013-03-12
- Inventor: Omer Tripp
- Applicant: Omer Tripp
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: VanLeeuwen & VanLeeuwen
- Agent Terrence J. Carroll
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F9/44

Abstract:
A system for detecting security vulnerabilities in computer software, including a cryptographic API identifier configured to identify a cryptographic API among the instructions of a computer software application, a path-to-source tracer configured to trace an information flow path among the instructions between the cryptographic API and a source that directly or indirectly provides data that are input to the cryptographic API, where a cryptographically-sensitive information carrier lies along the information flow path, a path-to-sink tracer configured to trace an information flow path among the instructions from the cryptographically-sensitive information carrier to a sink, and a security vulnerability identifier configured to provide a notification that the information flow path between the cryptographically-sensitive information carrier and the sink represents security vulnerability if the information flow path between the cryptographically-sensitive information carrier and the sink does not pass through a cryptographic API.
Public/Granted literature
Information query