发明申请
- 专利标题: DETECTING VULNERABILITIES IN WEB APPLICATIONS
- 专利标题(中): 检测WEB应用程序中的漏洞
-
申请号: US13440416申请日: 2012-04-05
-
公开(公告)号: US20130139267A1公开(公告)日: 2013-05-30
- 发明人: Yair Amit , Daniel Kalman , Omer Tripp
- 申请人: Yair Amit , Daniel Kalman , Omer Tripp
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A method, computer program product, and system for detecting vulnerabilities in web applications is described. A method may comprise determining one or more values associated with a web application that flow to response data associated with the web application. The one or more values may be modifiable by unreliable input. The method may further comprise generating a representation of the response data associated with the web application. The method may additionally comprise determining one or more potentially vulnerable portions of the response data based upon, at least in part, the one or more values modifiable by the unreliable input that flow to the response data associated with the web application, and the representation of the response data associated with the web application.
公开/授权文献
- US09124624B2 Detecting vulnerabilities in web applications 公开/授权日:2015-09-01
信息查询