Invention Grant
- Patent Title: Modular static application security testing
- Patent Title (中): 模块化静态应用安全测试
-
Application No.: US13932357Application Date: 2013-07-01
-
Publication No.: US09305168B2Publication Date: 2016-04-05
- Inventor: Achim D. Brucker , Thomas Deuster
- Applicant: Achim D. Brucker , Thomas Deuster
- Applicant Address: DE Walldorf
- Assignee: SAP SE
- Current Assignee: SAP SE
- Current Assignee Address: DE Walldorf
- Agency: Fish & Richardson P.C.
- Main IPC: H04L29/00
- IPC: H04L29/00 ; G06F21/57

Abstract:
Methods, systems, and computer-readable storage media for analyzing source code of an application. In some implementations, actions include determining, for at least one procedure invoked by the source code, a procedure specification specifying one or more conditions under which one or more parameters of the procedure are exploitable according to a parameter security specification; performing static application security testing on the source code by using the procedure specification on reaching an invocation of the procedure in the source code, including: comparing one or more invoking parameters of the invocation of the procedure to the conditions of the procedure specification; and determining whether the invocation of the procedure is exploitable.
Public/Granted literature
- US20150013011A1 MODULAR STATIC APPLICATION SECURITY TESTING Public/Granted day:2015-01-08
Information query