- 专利标题: Detection of second order vulnerabilities in web services
-
申请号: US13335439申请日: 2011-12-22
-
公开(公告)号: US10586049B2公开(公告)日: 2020-03-10
- 发明人: Yair Amit , Evgeny Beskrovny , Omer Tripp
- 申请人: Yair Amit , Evgeny Beskrovny , Omer Tripp
- 申请人地址: US NY Armonk
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY Armonk
- 代理机构: Cuenot, Forsythe & Kim, LLC
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F21/57 ; H04L29/08 ; G06F9/30 ; G07B17/00 ; H04W12/00
摘要:
A system for detecting a vulnerability in a Web service can include a processor configured to initiate executable operations including determining whether a Web service uses identity of a requester to select one of a plurality of different paths of a branch in program code of the Web service and, responsive to determining that the Web service does select one of a plurality of different paths of a branch according to identity of the requester, indicating that the Web service has a potential vulnerability.
公开/授权文献
信息查询