Invention Grant
- Patent Title: Application modification based on a security vulnerability
-
Application No.: US14992245Application Date: 2016-01-11
-
Publication No.: US09858423B2Publication Date: 2018-01-02
- Inventor: Roee Hay , Omer Tripp
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Terrile, Cannatti, Chambers & Holland, LLP
- Agent Stephen A. Terrile
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F21/31

Abstract:
In some examples, a method includes inserting monitoring instructions to be executed with a set of conditional operations and data type operations in an application and executing the application with a benign value. The method can also include storing at least one of result values and path constraints from the monitoring instructions, the result values comprising values generated by each conditional operation and each data type operation executed with the benign value. Furthermore, the method can include generating a prohibited value corresponding to a security vulnerability that satisfies the set of conditional operations and data type operations in the application based on the result values and the path constraints and modifying the application to prevent execution of the prohibited value.
Public/Granted literature
- US20170200012A1 Application Modification Based on a Security Vulnerability Public/Granted day:2017-07-13
Information query