System, method, and program for determining validity of character string
    1.
    发明专利
    System, method, and program for determining validity of character string 有权
    用于确定字符有效性的系统,方法和程序

    公开(公告)号:JP2011013810A

    公开(公告)日:2011-01-20

    申请号:JP2009155705

    申请日:2009-06-30

    CPC classification number: G06F21/577 G06F8/43 G06F11/3604 G06F21/563

    Abstract: PROBLEM TO BE SOLVED: To determine the validity of a character string generated by a program written in a programming language without executing the program.SOLUTION: The method for determining the validity of a character string generated by a program includes: abstracting a constraint between variables extracted from a source code for a programming language, wherein the variables include a string declaration and the definition of each variable is unique, describing the constraint in M2L, giving a specification to determine whether the character string is safe or unsafe in M2L, and evaluating the validity of the character string on an M2L solver on the basis of the constraint on the variables and the specification to determine whether the string is safe or unsafe.

    Abstract translation: 要解决的问题:确定由编程语言编写的程序生成的字符串的有效性,而不执行程序。解决方案:用于确定程序生成的字符串的有效性的方法包括:在变量之间抽象约束 从编程语言的源代码提取,其中变量包括字符串声明,并且每个变量的定义是唯一的,描述了M2L中的约束,给出了在M2L中确定字符串是安全还是不安全的规范,以及评估 在M2L求解器上的字符串的有效性基于对变量的约束和规范来确定字符串是否安全或不安全。

    ERKENNUNG VON SCHWACHSTELLEN FÜR DOM-BASIERTES CROSS-SITE-SCRIPTING

    公开(公告)号:DE102012218704A1

    公开(公告)日:2013-05-02

    申请号:DE102012218704

    申请日:2012-10-15

    Applicant: IBM

    Abstract: Prüfen einer web-basierten Anwendung auf Sicherheitsschwachstellen. Wenigstens eine Client-Anforderung, die Nutzdaten mit einer eindeutigen Kennung enthält, kann zu einer web-basierten Anwendung übertragen werden. Eine HTML-Antwort und ein zugehöriges Dokumentenobjektmodell-(DOM-)Objekt kann von der web-basierten Anwendung empfangen werden. Inhalt, der den Nutzdaten entspricht, kann in dem DOM-Objekt über die eindeutige Kennung identifiziert werden. Ein Abschnitt des DOM-Objekts, der die Nutzdaten enthält, kann als nicht vertrauenswürdig identifiziert werden.

    Testing web application for security vulnerabilities by identifying known payload in DOM

    公开(公告)号:GB2496730A

    公开(公告)日:2013-05-22

    申请号:GB201218726

    申请日:2012-10-18

    Applicant: IBM

    Abstract: A client 120 request 130 comprising a payload 132 an injected script for example is communicated to a web-based application 112. The payload has a unique identifier. Response HTML 134 with an associated Document Object Model (DOM) object 136 is received from the web-based application and content corresponding to the payload is identified in the DOM object via its unique identifier. A section of the DOM object comprising the payload is then identified as un-trusted. A DOM abstraction 126 may be generated from the DOM object comprising a section of the DOM object containing the content corresponding to the payload whilst, preferably, excluding sections of the DOM object not comprising said content. The response HTML is then preferably rendered using the DOM abstraction in lieu of the DOM object. A static security analysis of the response HTML may be performed when rendering to identify whether any access to a DOM abstraction retrieves content corresponding to the payload and, if so, a flag is generated to indicate that a vulnerability exists within the web-based application.

Patent Agency Ranking