IP Library Granted Patent US 8,800,042
Granted Patent B2
US 8,800,042 · App. 11/465,916 · Granted Aug 5, 2014

Secure web application development and execution environment

Inventors: Caleb Sima (Woodstock, GA); Bryan Sullivan (Duluth, GA)
Assignee: Hewlett-Packard Development Company, L.P.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,800,042
App. No.
11/465,916
Filed
Aug 21, 2006
Granted
Aug 5, 2014
Kind
B2
Art Unit
2436
USPC
726/25
Abstract

Providing secure web application development and operation. In a web development environment, code developed for the web application is analyzed to identify vulnerabilities and remedial actions are identified. The remedial actions may be automatically invoked or a developer can be prompted to take particular actions to remediate the vulnerability.

Claims (39)

1. A method for developing a secure web application, the method comprising:

in a web application development environment:

analyzing code, by a processor, associated with a web application to identify at least one security vulnerability;

comparing the at least one security vulnerability to a vulnerability datastore, which stores validation routines for verifying input data associated with the at least one security vulnerability, to identify a recommended validation routine; and

alleviating, by the processor, the security vulnerability by invoking a developer interface that enables a developer of the web application to select from a group of remediation actions including:

generating remediation code and inserting the remediation code into the web application;

generating remediation code and replacing a section of insecure code within the web application with the remediation code.

2. The method of claim 1 , further comprising modifying the source code associated with the web application to include the remediation.

3. The method of claim 1 , wherein the step of analyzing code associated with the web application comprises analyzing source code associated with the web application.

4. The method of claim 1 , wherein the step of analyzing code associated with the web application comprises performing a static analysis on binary code associated with the web application.

5. The method of claim 1 , further comprising remediating the operation of the web application if a restrictive policy is violated.

6. The method of claim 1 , wherein the remediation code entered into the secure web application to alleviate a security vulnerability operates to enable a developer of the web application to validate the vulnerability.

7. The method of claim 6 , wherein the remediation code further enables the steps of:

displaying the identity of the security vulnerability to a developer of the web application; and

displaying a recommended validation routine to be applied to the at least one security vulnerability.

8. The method of claim 1 , wherein the remediation code entered into the secure web application to alleviate a security vulnerability operates to automatically remediate the web application vulnerability.

9. The method of claim 8 , further comprising comparing the at least one security vulnerability to a vulnerability datastore to identify a remediation action to be taken.

10. A non-transitory computer-readable storage medium that stores a web application development environment program that, when executed, causes a processor to:

operate a vulnerability identification module to analyze code of a web application and identify one or more vulnerabilities within said code;

compare the one or more vulnerabilities to a vulnerability datastore, which stores validation routines for verifying input data associated with the at least one security vulnerability, to identify a recommended validation routine; and

operate a remediation module to alleviate one or more of the vulnerabilities identified by the vulnerability detection module by switching at least one existing input authentication feature of said code between an enabled state and a disabled state.

11. The computer-readable storage medium of claim 10 , wherein the web application development environment program further causes the processor to scan source code associated with the web application to identify said one or more vulnerabilities.

12. The computer-readable storage medium of claim 10 , wherein the web application development environment program further causes the processor to operate an interactive wizard as part of the remediation module, the interactive wizard enables a developer of the web application to validate the vulnerabilities.

13. The computer-readable storage medium of claim 12 , wherein the web application development environment program further causes the processor to operate the interactive wizard to provide a recommended validation routine for at least one of the vulnerabilities to the developer.

14. The computer-readable storage medium of claim 10 , wherein the web application development environment program further causes the processor to operate the remediation module to process vulnerability data received from a web application assessment tool.

15. The computer-readable storage medium of claim 10 , wherein the web application development environment program further causes the processor to operate the remediation module to automatically modify source code associated with the web application to alleviate a vulnerability.

16. A system for developing a secure web application, the system comprising:

a processor;

a web application development environment stored on a computer-readable storage medium and executed by the processor; and

a vulnerability detection module integrated with operations of the web application development environment, the vulnerability detection module comprising:

logic configured to analyze code associated with a web application being developed via the web application development environment;

logic configured to identify vulnerabilities in the web application;

logic configured to compare at least one security vulnerability to a vulnerability datastore, which stores validation routines for verifying input data associated with the at least one security vulnerability, to identify a recommended validation routine; and

a remediation module integrated with operations of the web application development environment, the remediation module comprising:

logic configured to provide remediation measures to alleviate at least one of said vulnerabilities by selectively forcing at least one existing authentication feature of said code to be enabled or disabled.

17. The system of claim 16 , wherein the vulnerability detection module scans source code of said web application.

18. The system of claim 16 , wherein the vulnerability detection module analyzes binary code of said web application.

19. The system of claim 16 , wherein the remediation module includes a wizard that provides remediation options to a developer of said web application.

20. The system of claim 16 , wherein the remediation module automatically identifies a remediation measure and implements the remediation measure.

Assignments (10)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2007
From: HEWLETT-PACKARD COMPANY
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 020174/0373 →
MERGER Recorded Nov 26, 2007
From: S.P.I. DYNAMICS INCORPORATED
To: HEWLETT-PACKARD COMPANY
Reel/Frame 020143/0829 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2006
From: SIMA, CALEB; SULLIVAN, BRYAN
To: S.P.I. DYNAMICS INCORPORATED
Reel/Frame 018151/0427 →
Continuity (2)
Continuation In Part 10908520 · May 16, 2005
Related Publication 20060282897A1 · Dec 14, 2006