Invention Grant
- Patent Title: Automatic synthesis of unit tests for security testing
-
Application No.: US14305280Application Date: 2014-06-16
-
Publication No.: US09892258B2Publication Date: 2018-02-13
- Inventor: Daniel Kalman , Ory Segal , Omer Tripp , Omri Weisman
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agency: Cuenot, Forsythe & Kim, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/57 ; G06F21/10

Abstract:
Performing security analysis on a computer program under test (CPUT). The CPUT can be analyzed to identify data pertinent to potential security vulnerabilities of the CPUT. At least a first unit test configured to test a particular unit of program code within the CPUT can be automatically synthesized. The first unit test can be configured to initialize at least one parameter used by the particular unit of program code within the CPUT, and can be provided at least a first test payload configured to exploit at least one potential security vulnerability of the CPUT. The first unit test can be dynamically processed to communicate the first test payload to the particular unit of program code within the CPUT. Whether the first test payload exploits an actual security vulnerability of the CPUT can be determined, and a security analysis report can be output.
Public/Granted literature
- US20140298474A1 AUTOMATIC SYNTHESIS OF UNIT TESTS FOR SECURITY TESTING Public/Granted day:2014-10-02
Information query