Invention Grant
US09363284B2 Testing web applications for security vulnerabilities with metarequests
有权
使用metarequests测试Web应用程序的安全漏洞
- Patent Title: Testing web applications for security vulnerabilities with metarequests
- Patent Title (中): 使用metarequests测试Web应用程序的安全漏洞
-
Application No.: US14103221Application Date: 2013-12-11
-
Publication No.: US09363284B2Publication Date: 2016-06-07
- Inventor: Marco Pistoia , Omer Tripp
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Harrington & Smith
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08

Abstract:
A method includes instantiating, in response to a request by an executing application, an input data object with one or more uninitialized fields and traversing a path toward a sink in the executing application to a branching point of the executing application. In response to reaching the branching point, one or more parameters are provided for some or all of the one or more uninitialized fields of the input data object, wherein the one or more parameters were determined prior to beginning of execution of the executing application to cause a branch to be taken by the executing application toward the sink. The path is traversed toward the sink at least by following the branch in the executing application. Apparatus and computer program products are also disclosed.
Public/Granted literature
- US20150163237A1 TESTING WEB APPLICATIONS FOR SECURITY VULNERABILITIES WITH METAREQUESTS Public/Granted day:2015-06-11
Information query