- 专利标题: Detecting vulnerabilities in web applications
-
申请号: US13307780申请日: 2011-11-30
-
公开(公告)号: US09032529B2公开(公告)日: 2015-05-12
- 发明人: Yair Amit , Daniel Kalman , Omer Tripp
- 申请人: Yair Amit , Daniel Kalman , Omer Tripp
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Holland & Knight LLP
- 代理商 Brian J. Colandreo, Esq.; Jeffrey T. Placker, Esq.
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L29/08 ; H04W12/12
摘要:
A method, computer program product, and system for detecting vulnerabilities in web applications is described. A method may comprise determining one or more values associated with a web application that flow to response data associated with the web application. The one or more values may be modifiable by unreliable input. The method may further comprise generating a representation of the response data associated with the web application. The method may additionally comprise determining one or more potentially vulnerable portions of the response data based upon, at least in part, the one or more values modifiable by the unreliable input that flow to the response data associated with the web application, and the representation of the response data associated with the web application.
公开/授权文献
- US20130139266A1 DETECTING VULNERABILITIES IN WEB APPLICATIONS 公开/授权日:2013-05-30
信息查询