IP Library Patent Application 12234303
Patent Application
App. No. 12/234,303

SYSTEM AND METHOD FOR DETECTING SECURITY DEFECTS IN APPLICATIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/234,303
Abstract

A system and method for detecting vulnerabilities in a deployed web application includes developing a profile of acceptable behavior for inbound communication and outbound communication of a web application. The method also includes receiving a current inbound communication and a current outbound communication from the web application. The current inbound communication includes an inbound user request and the current outbound communication is in response to the current inbound communication. The current inbound communication and the current outbound communication are validated with the profile of acceptable behavior to identify an anomaly. The identified anomaly includes an occurrence of an acceptable behavior for the current inbound communication in combination with an occurrence of an unacceptable behavior for the current outbound communication.

Claims (29)

1 . A method for detecting vulnerabilities in a deployed web application, the method comprising:

developing a profile of acceptable behavior for inbound communication and outbound communication of a web application;

receiving a current inbound communication including an inbound user request and a current outbound communication from the web application that is in response to the current inbound communication; and

validating the current inbound communication and the current outbound communication with the profile of acceptable behavior to identify an anomaly, the identified anomaly including an occurrence of an acceptable behavior for the current inbound communication in combination with an occurrence of an unacceptable behavior for the current outbound communication.

2 . The method of claim 1 , further comprising automatically developing the profile of acceptable behavior.

3 . The method of claim 1 , further comprising automatically updating the profile of acceptable behavior as users interact with the application.

4 . The method of claim 1 , further comprising receiving and analyzing the anomaly by at least one threat-detection engine to determine if there is a vulnerability in the web application which caused the anomaly.

5 . The method of claim 1 , further comprising triggering an alert when an anomaly is identified.

6 . The method of claim 5 , further comprising sending the alert to a database where it is retrieved for further analysis.

7 . The method of claim 5 , further comprising sending the alert to a user console for further analysis.

8 . A system for detecting defects in a web application, the system comprising:

a dynamic profiling module configured to develop a profile of acceptable behavior for inbound communication and outbound communication of a web application; and

a collaborative detection module configured to receive a current inbound communication including an inbound user request and a current outbound communication from the web application that is in response to the current inbound communication, to validate the current inbound communication and the current outbound communication with the profile of acceptable behavior to identify an anomaly, the identified anomaly including an occurrence of an acceptable behavior for the current inbound communication in combination with an occurrence of an unacceptable behavior for the current outbound communication.

9 . The system of claim 8 , further comprising an adaptation module configured to monitor the inbound and outbound communication and modify the profile of acceptable behavior during the life of the web application.

10 . The system of claim 8 , wherein the collaborative detection module further comprises an outgoing detection module configured to monitor and model the web applications behavior independently or in response to users accessing the web application.

11 . The system of claim 8 , wherein the collaborative detection module further comprises an outgoing detection module configured to monitor and model the web application's behavior independently and in response to users accessing the web application.

12 . The system of claim 8 , wherein the dynamic profiling module is configured to automatically develop the profile of acceptable behavior.

13 . The system of claim 9 , wherein the adaptation module is configured to automatically update the profile of acceptable behavior as users interact with the application.

14 . The system of claim 8 , further comprising an analysis and correlation module coupled to the collaborative detection module and configured to receive and analyze the anomaly by at least one threat-detection engine to determine if there is a vulnerability in the web application which caused the anomaly

15 . A means for detecting vulnerabilities in a deployed web application, the means comprising:

a means for developing a profile of acceptable behavior for inbound communication and outbound communication of a web application;

a means for receiving a current inbound communication including an inbound user request and a current outbound communication from the web application that is in response to the current inbound communication; and

a means for validating the current inbound communication and the current outbound communication with the profile of acceptable behavior to identify an anomaly, the identified anomaly including an occurrence of an acceptable behavior for the current inbound communication in combination with an occurrence of an unacceptable behavior for the current outbound communication.

16 . The method of claim 1 , further comprising a means for automatically developing the profile of acceptable behavior.

17 . The method of claim 1 , further comprising a means for automatically updating the profile of acceptable behavior as users interact with the application.

18 . The method of claim 1 , further comprising a means for receiving and analyzing the anomaly by at least one threat-detection engine to determine if there is a vulnerability in the web application which caused the anomaly.

19 . The method of claim 1 , further comprising a means for triggering an alert when an anomaly is identified.

20 . The method of claim 5 , further comprising a means for sending the alert to a database where it is retrieved for further analysis.

21 . The method of claim 5 , further comprising a means for sending the alert to a user console for further analysis.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Jul 11, 2012
From: SILICON VALLEY BANK
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 028526/0001 →
RELEASE OF SECURITY INTEREST Recorded Jul 10, 2012
From: SILICON VALLEY BANK
To: TW BREACH SECURITY, INC.
Reel/Frame 028519/0348 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDRESS OF THE RECEIVING PARTY PREVIOUSLY RECORDED ON REEL 027867 FRAME 0199. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Mar 19, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027886/0058 →
SECURITY AGREEMENT Recorded Mar 15, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027867/0199 →
SECURITY AGREEMENT Recorded Mar 8, 2011
From: TW BREACH SECURITY, INC.
To: SILICON VALLEY BANK
Reel/Frame 025914/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2011
From: TW BREACH SECURITY, INC.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 025590/0351 →
MERGER Recorded Oct 21, 2010
From: BREACH SECURITY, INC.
To: TW BREACH SECURITY, INC.
Reel/Frame 025169/0652 →
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2010
From: SRBA #5, L.P. (SUCCESSOR IN INTEREST TO ENTERPRISE PARTNERS V, L.P. AND ENTERPRISE PARTNERS VI, L.P.); EVERGREEN PARTNERS US DIRECT FUND III, L.P.; EVERGREEN PARTNERS DIRECT FUND III (ISRAEL) L.P.; EVERGREEN PARTNERS DIRECT FUND III (ISRAEL 1) L.P.
To: BREACH SECURITY, INC.
Reel/Frame 024869/0883 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2008
From: OVERCASH, KEVIN
To: BREACH SECURITY, INC.
Reel/Frame 021818/0527 →