IP Library Granted Patent US 8,656,495
Granted Patent B2
US 8,656,495 · App. 11/560,969 · Granted Feb 18, 2014

Web application assessment based on intelligent generation of attack strings

Inventors: Caleb Sima (Woodstock, GA); Raymond Kelly (Loganville, GA); William M. Hoffman (Atlanta, GA)
Assignee: Hewlett-Packard Development Company, L.P.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,656,495
App. No.
11/560,969
Filed
Nov 17, 2006
Granted
Feb 18, 2014
Kind
B2
Art Unit
2434
USPC
726/25
Abstract

A web application is more efficiently analyzed by intelligently generating attack sequences to be used in the assessment. Rather than simply sending a canned list of static strings at a web application, the operation of the web application is analyzed to determine the filtering and acceptance characteristics of the web site. As this information is ascertained, a vocabulary of allowed symbols is created. This vocabulary is used in the building of attack strings and as such, the number of attack strings fired at the web application is greatly reduced, as well as the number of false positives.

Claims (36)

1. A method for conducting a web application vulnerability assessment, the method comprising the steps of:

conducting, using a processor, a crawl of a web application to identify input fields;

identifying a domain of symbols that can be used as input for the input fields of the web application;

determining which of the symbols are filtered and which are accepted by the web application;

building a vocabulary comprising the symbols that are accepted by the web application;

generating one or more attack strings based at least in part on the vocabulary;

sending the attack strings to the web application; and

identifying vulnerabilities uncovered by the step of sending the attack strings.

2. The method of claim 1 , wherein a database of static attack strings is provided and the step of generating one or more attack strings further comprises selecting attack strings from the static attack stings that are constructed with symbols in the vocabulary.

3. The method of claim 1 , wherein the step of determining which symbols are filtered and which are echoed by the web application further comprises the steps of:

creating a first string, the first string containing one or more symbols;

sending the first string as input to the web application;

receiving a response from the web application; and

analyzing the response to identify symbols that are echoed and filtered by the web application.

4. The method of claim 3 , further comprising the steps of:

generating a next string, the next string containing one or more symbols that have not already been determined to be filtered symbols;

sending the next string as input to the web application;

receiving a response from the web application;

analyzing the response to identify symbols that are echoed and filtered by the web application; and

continuing at the generating step until all symbols have been identified as echoed or filtered.

5. The method of claim 4 , wherein the step of generating one or more attack strings based at least in part on the vocabulary may be the same step as the step of generating a next string.

6. The method of claim 4 , wherein the step of generating one or more attack strings based at least in part on the vocabulary does not occur until the vocabulary has been completely built.

7. A method for conducting a web application vulnerability assessment, the method comprising the steps of:

determining, using a processor, which symbols of a domain of available symbols are filtered and which symbols are accepted by an input server of a web application;

building a vocabulary consisting of the symbols that are accepted by the web application;

generating one or more attack strings based at least in part on the vocabulary; and

assessing vulnerability of the web application by using the attack strings.

8. The method of claim 7 , wherein the domain of available symbols is the constructs of the markup language used to generate the web pages of the web application, and the step of determining which of the symbols are filtered and which are accepted by the input server of the web application comprises the steps of:

sending one or more of the symbols in a probe to the web application;

receiving a response from the web application that includes an echo of one or more of the symbols in the probe; and

analyzing the response to identify which symbols were echoed back.

9. The method of claim 7 , wherein the step of generating one or more attack strings based at least in part on the vocabulary further comprises building attack strings using constructs of the markup language that are included in the vocabulary.

10. The method of claim 7 , wherein the domain of available symbols is the constructs of the attack technique being employed, and the step of determining which of the symbols are filtered and which are accepted by the input server of the web application comprises the steps of:

sending one or more of the symbols in a probe to the web application;

receiving a response from the web application indicating whether the probe was accepted or rejected;

applying an algorithm to separate out the one or more symbols in the probe to send further probes and thereby isolate the symbols invoking the rejection.

Assignments (10)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2007
From: HEWLETT-PACKARD COMPANY
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 020188/0644 →
MERGER Recorded Nov 26, 2007
From: S.P.I. DYNAMICS INCORPORATED
To: HEWLETT-PACKARD COMPANY
Reel/Frame 020143/0829 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2006
From: SIMA, CALEB; KELLY, RAYMOND; HOFFMAN, WILLIAM M
To: S.P.I. DYNAMICS INCORPORATED
Reel/Frame 018532/0270 →
Continuity (1)
Related Publication 20080120722A1 · May 22, 2008