IP Library Granted Patent US 8,528,093
Granted Patent B1
US 8,528,093 · App. 11/734,114 · Granted Sep 3, 2013

Apparatus and method for performing dynamic security testing using static analysis data

Inventors: Toshinari Kureha (Redwood City, CA); Koorosh Nouri (Foster City, CA); Arthur Do (Danville, CA); Brian Chess (Mountain View, CA); Roger Thornton (San Jose, CA)
Assignee: Hewlett-Packard Development Company, L.P.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,528,093
App. No.
11/734,114
Filed
Apr 11, 2007
Granted
Sep 3, 2013
Kind
B1
Art Unit
2491
USPC
726/25
Abstract

A computer readable storage medium includes executable instructions to perform a static analysis of a set of target code to identify a first set of security issues. A dynamic analysis of the target code is executed to identify a second set of security issues. The first set of security issues and the second set of security issues are compared and common security issues are reported.

Claims (18)

1. A non-transitory computer readable storage medium, comprising executable instructions to:

execute a dynamic analysis of target code to identify a first set of identified security issues, wherein each security issue in the first set of identified security issues includes a first security category, a complete Uniform Resource Locator (URL), and a first common parameter name;

perform a static analysis of the target code to identify a second set of identified security issues wherein the first set of identified security issues are used to tailor the static analysis and wherein each security issue in the second set of identified security issues includes a second security category, a partial URL, and a second common parameter name; and

compare the first set of identified security issues and the second set of identified security issues to report common identified security issues wherein common identified security issues include the first security category that matches the second category, the complete URL that matches the partial URL, and the first common parameter name that matches the second common parameter name.

2. The non-transitory computer readable storage medium of claim 1 wherein the executable instructions to perform a static analysis include executable instructions to analyze configuration files to map a URL to a subset of code and thereby provide access information for a dynamic analysis.

3. The non-transitory computer readable storage medium of claim 2 further comprising executable instructions to analyze configuration files to map the URL to a class.

4. The non-transitory computer readable storage medium of claim 1 wherein the executable instructions to perform a static analysis include executable instructions to access a list equating and subsets of code to provide access information for a dynamic analysis.

5. The non-transitory computer readable storage medium of claim 4 further comprising equating URLs with classes.

6. The non-transitory computer readable storage medium of claim 1 further comprising executable instructions to embed monitors in the set of target code.

7. The non-transitory computer readable storage medium of claim 6 further comprising executable instructions to receive runtime information from the monitors during dynamic analysis.

8. The non-transitory computer readable storage medium of claim 7 wherein the runtime information includes an accessed and corresponding subset of the set target code.

9. The non-transitory computer readable storage medium of claim 8 further comprising executable instructions to associate the URL with a class.

10. The non-transitory computer readable storage medium of claim 1 further comprising monitors in the target code to generate runtime information when the target code is executed.

11. The non-transitory computer readable storage medium of claim 10 wherein the runtime information includes a URL and a corresponding class file.

12. A non-transitory computer readable storage medium, comprising executable instructions to:

execute a dynamic analysis of target code to identify a first set of identified security issues, wherein the dynamic analysis includes retrieving Uniform Resource Locators (URLs) and corresponding class files from monitors in the target code and wherein each security issue in the first set of identified security issues includes a first security category, a complete URL, and a first common parameter name;

perform a static analysis of the target code to identify a second set of identified security issues, wherein the first set of identified security issues are used to tailor the static analysis and wherein each security issue in the second set of identified security issues includes a second security category, a partial URL, and a second common parameter name; and

compare the first set of identified security issues and the second set of identified security issues to report common security issues wherein common identified security issues include the first security category that matches the second category, the complete URL that matches the partial URL, and the first common parameter name that matches the second common parameter name.

Assignments (11)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
MERGER Recorded Nov 16, 2012
From: FORTIFY SOFTWARE, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029316/0274 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: HEWLETT-PACKARD SOFTWARE, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029316/0280 →
CERTIFICATE OF CONVERSION Recorded Apr 20, 2011
From: FORTIFY SOFTWARE, INC.
To: FORTIFY SOFTWARE, LLC
Reel/Frame 026155/0089 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2007
From: KUREHA, TOSHINARI; NOURI, KOOROSH; DO, ARTHUR; CHESS, BRIAN
To: FORTIFY SOFTWARE, INC.
Reel/Frame 019627/0365 →
Continuity (1)
Provisional Application 60791692 · Apr 12, 2006