Invention Grant
- Patent Title: System and method for facilitating static analysis of software applications
-
Application No.: US14577388Application Date: 2014-12-19
-
Publication No.: US09645800B2Publication Date: 2017-05-09
- Inventor: Mansi Sheth
- Applicant: Veracode, Inc.
- Applicant Address: US MA Burlington
- Assignee: Veracode, Inc.
- Current Assignee: Veracode, Inc.
- Current Assignee Address: US MA Burlington
- Agency: Goodwin Procter LLP
- Main IPC: G06F9/44
- IPC: G06F9/44 ; G06F9/45 ; G06F21/57 ; G06F11/36

Abstract:
In system for enabling static vulnerability analysis of a software/web application that includes an indirectly modeled language portion and a directly modeled language portion, an indirectly modeled language information extractor select nodes of certain types from a syntax tree corresponding to the indirectly modeled language source code. Generally, the types of nodes that are selected are relevant to taint propagation. For one or more of the selected nodes, one or more statements corresponding to one or more of a type of the node, an input to the node, and an object associated with the node are generated. A static analyzer configured for a directly modeled language may perform vulnerability analysis of the software/web application using the generated statements.
Public/Granted literature
- US20160179486A1 SYSTEM AND METHOD FOR FACILITATING STATIC ANALYSIS OF SOFTWARE APPLICATIONS Public/Granted day:2016-06-23
Information query