发明授权
- 专利标题: Detection of DOM-based cross-site scripting vulnerabilities
- 专利标题(中): 检测基于DOM的跨站点脚本漏洞
-
申请号: US13447904申请日: 2012-04-16
-
公开(公告)号: US09223977B2公开(公告)日: 2015-12-29
- 发明人: Yair Amit , Yinnon A. Haviv , Daniel Kalman , Omer Tripp , Omri Weisman
- 申请人: Yair Amit , Yinnon A. Haviv , Daniel Kalman , Omer Tripp , Omri Weisman
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Cuenot, Forsythe & Kim, LLC
- 主分类号: G06F21/55
- IPC分类号: G06F21/55 ; G06F21/56 ; G06F21/52 ; G06F21/57
摘要:
Testing a Web-based application for security vulnerabilities. At least one client request including a payload having a unique identifier can be communicated to the Web-based application. Response HTML and an associated Document Object Model (DOM) object can be received from the Web-based application. Content corresponding to the payload can be identified in the DOM object via the unique identifier. A section of the DOM object including the payload can be identified as un-trusted.
公开/授权文献
信息查询