Invention Grant
US09118713B2 System and a method for automatically detecting security vulnerabilities in client-server applications
有权
系统和一种自动检测客户端 - 服务器应用程序安全漏洞的方法
- Patent Title: System and a method for automatically detecting security vulnerabilities in client-server applications
- Patent Title (中): 系统和一种自动检测客户端 - 服务器应用程序安全漏洞的方法
-
Application No.: US13627928Application Date: 2012-09-26
-
Publication No.: US09118713B2Publication Date: 2015-08-25
- Inventor: Prithvi Bisht , Timothy Hinrichs , Venkatesan Natarajan Venkatakrishnan
- Applicant: THE BOARD OF TRUSTEES OF THE UNIVERSITY OF ILLINOIS
- Applicant Address: US IL Urbana
- Assignee: THE BOARD OF TRUSTEES OF THE UNIVERSITY OF ILLINOIS
- Current Assignee: THE BOARD OF TRUSTEES OF THE UNIVERSITY OF ILLINOIS
- Current Assignee Address: US IL Urbana
- Agency: Michael Best & Friedrich LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; H04L29/06 ; G06F21/53 ; G06F21/57

Abstract:
A method for automatically detecting security vulnerabilities in a client-server application where a client is connected to a server. The method is implemented by a computer having a processor and a software program stored on a non-transitory computer readable medium. The method includes automatically extracting, with the software program at the client, a description of one or more validation checks on inputs performed by the client. The method also includes analyzing the server, with the software program by using the one or more validation checks on inputs performed by the client, to determine whether the server is not performing validation checks that the server must be performing. The method further includes determining that security vulnerabilities in the client-server application exist when the server is not performing validation checks that the server must be performing. A method further proposes preventing parameter tampering attacks on a running client-server application by enforcing the one or more validation checks on inputs performed by the client on each input that is submitted to the server.
Public/Granted literature
- US20130091578A1 SYSTEM AND A METHOD FOR AUTOMATICALLY DETECTING SECURITY VULNERABILITIES IN CLIENT-SERVER APPLICATIONS Public/Granted day:2013-04-11
Information query