Invention Grant
- Patent Title: Detecting vulnerabilities in web applications
- Patent Title (中): 检测Web应用程序中的漏洞
-
Application No.: US13440416Application Date: 2012-04-05
-
Publication No.: US09124624B2Publication Date: 2015-09-01
- Inventor: Yair Amit , Daniel Kalman , Omer Tripp
- Applicant: Yair Amit , Daniel Kalman , Omer Tripp
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Holland & Knight LLP
- Agent Brian J. Colandreo, Esq.; Jeffrey T. Placker, Esq.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04W12/12 ; H04L29/08

Abstract:
A method, computer program product, and system for detecting vulnerabilities in web applications is described. A method may comprise determining one or more values associated with a web application that flow to response data associated with the web application. The one or more values may be modifiable by unreliable input. The method may further comprise generating a representation of the response data associated with the web application. The method may additionally comprise determining one or more potentially vulnerable portions of the response data based upon, at least in part, the one or more values modifiable by the unreliable input that flow to the response data associated with the web application, and the representation of the response data associated with the web application.
Public/Granted literature
- US20130139267A1 DETECTING VULNERABILITIES IN WEB APPLICATIONS Public/Granted day:2013-05-30
Information query