Invention Grant
- Patent Title: Verifying application security vulnerabilities
- Patent Title (中): 验证应用程序安全漏洞
-
Application No.: US14574790Application Date: 2014-12-18
-
Publication No.: US09160762B2Publication Date: 2015-10-13
- Inventor: Nevon C. Brake , Paul Ionescu , Iosif Viorel Onut , John T. Peyton, Jr. , Wayne Duncan Smith
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agency: Cuenot, Forsythe & Kim, LLC
- Priority: CA2777434 20120518
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Verifying application security vulnerabilities includes receiving a source code to analyze, performing a static analysis using the received source code and generating a vulnerability call trace for the received source code. Responsive to a determination that all static analysis results are not validated, mock objects are generated using the vulnerability call trace and a unit test is created using the generated mock objects. The unit test is executed using the generated mock objects and responsive to a determination that an identified vulnerability was validated; a next static analysis result is selected. Responsive to a determination that all static analysis results are validated, results and computed unit tests are reported.
Public/Granted literature
- US20150156216A1 VERIFYING APPLICATION SECURITY VULNERABILITIES Public/Granted day:2015-06-04
Information query