IP Library Granted Patent US 8,695,027
Granted Patent B2
US 8,695,027 · App. 13/173,218 · Granted Apr 8, 2014

System and method for application security assessment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,695,027
App. No.
13/173,218
Granted
Apr 8, 2014
Kind
B2
Abstract

A system and method in one embodiment includes modules for running a test script to generate a request to a target application, receiving a response from the target application, and running a detector script to inspect the response for a vulnerability. More specific embodiments include a target web site, populating a work in a queue, where the work corresponds to content in the response, and running a second test script or detector script to generate a follow-up request to the application if the vulnerability has been identified in the response. Other embodiments include extracting the work from the queue, and running a second test script corresponding to the extracted work. Other embodiments include storing an injection in an injection cache, de-registering the injection from the injection cache if it is identified in the response, and re-crawling the application, if the injection has not been de-registered from the injection cache.

Claims (64)

1. A method comprising:

running at least one test script to generate a request to a target application associated with a web site;

receiving a response from the target application;

running at least one detector script to inspect the response for at least one vulnerability;

identifying at least one JavaScript associated with the web site;

adding the at least one JavaScript to a queue in a queue framework;

running an additional script that tests for vulnerabilities specific to the at least one JavaScript;

running a plurality of test scripts in parallel to generate respective requests to a plurality of pages at the web site, wherein the plurality of test scripts correspond, at least, to web content on a first one of the plurality of pages, and to a form on a second one of the plurality of pages;

collecting corresponding responses from the plurality of pages; and

running a plurality of detector scripts to inspect the corresponding responses from the plurality of pages.

2. The method of claim 1 , wherein the target application is associated with a web page.

3. The method of claim 2 , wherein the at least one test script is selected from a group comprising banner test, crawl test, page test, and residual test.

4. The method of claim 2 , further comprising populating a plurality of work in a plurality of queues, wherein the plurality of work comprises one or more of site map, logout, evidence, authentication, pages, links, work entry, scripts, vulnerabilities, and errors.

5. The method of claim 4 , further comprising:

identifying a page in a site map queue;

searching the plurality of queues for at least one reference to the page; and

adding page information to a report if the at least one reference is found.

6. The method of claim 1 , further comprising populating a work in at least one queue.

7. The method of claim 6 , wherein the work corresponds to a content in the response.

8. The method of claim 6 , further comprising:

extracting the work from the at least one queue; and

running a second test script corresponding to the extracted work.

9. The method of claim 1 , further comprising running a second test script to generate a follow-up request to the target application if the at least one vulnerability has been identified in the response.

10. The method of claim 1 , further comprising running a second detector script to generate a follow-up request to the target application if the at least one vulnerability has been identified in the response.

11. The method of claim 1 , further comprising:

storing at least one injection in an injection cache;

de-registering the at least one injection from the injection cache if the at least one injection is identified in the response; and

re-crawling the target application, if the at least one injection has not been de-registered from the injection cache.

12. The method of claim 1 , further comprising adding at least one test script, at least one detector script and at least one queue.

13. An apparatus comprising:

a memory element configured to store data;

a network interface; and

a computing processor operable to execute instructions associated with the data, wherein the network interface, computing processor and the memory element cooperate such that the apparatus is configured for:

running at least one test script to generate a request to a target application associated with a web site;

receiving a response from the target application;

running at least one detector script to inspect the response for at least one vulnerability;

identifying at least one JavaScript associated with the web site;

adding the at least one JavaScript to a queue in a queue framework;

running an additional script that tests for vulnerabilities specific to the at least one JavaScript;

running a plurality of test scripts in parallel to generate respective requests to a plurality of pages at the web site, wherein the plurality of test scripts correspond, at least, to web content on a first one of the plurality of pages, and to a form on a second one of the plurality of pages;

collecting corresponding responses from the plurality of pages; and

running a plurality of detector scripts to inspect the corresponding responses from the plurality of pages.

14. The apparatus of claim 13 , wherein the processor is operable to perform further instructions comprising populating a work in at least one queue.

15. The apparatus of claim 13 , wherein the processor is operable to perform further instructions comprising:

storing at least one injection in an injection cache;

de-registering the at least one injection from the injection cache if the at least one injection is identified in the response; and

re-crawling the target application, if the at least one injection has not been de-registered from the injection cache.

16. The apparatus of claim 13 wherein the processor is operable to execute further instructions associated with a feed module, the further instructions comprising adding at least one test script, at least one detector script and at least one queue.

17. A non-transitory computer readable storage media that includes code for execution and when executed by a processor is operable to perform operations comprising:

running at least one test script to generate a request to a target application associated with a web site;

receiving a response from the target application;

running at least one detector script to inspect the response for at least one vulnerability;

identifying at least one JavaScript associated with the web site;

adding the at least one JavaScript to a queue in a queue framework;

running an additional script that tests for vulnerabilities specific to the at least one JavaScript;

running a plurality of test scripts in parallel to generate respective requests to a plurality of pages at the web site, wherein the plurality of test scripts correspond, at least, to web content on a first one of the plurality of pages, and to a form on a second one of the plurality of pages;

collecting corresponding responses from the plurality of pages; and

running a plurality of detector scripts to inspect the corresponding responses from the plurality of pages.

18. The media of claim 16 , the processor being operable to perform further operations comprising populating a work in at least one queue.

19. The media of claim 16 , the processor being operable to perform further operations comprising:

storing at least one injection in an injection cache;

de-registering the at least one injection from the injection cache if the at least one injection is identified in the response; and

re-crawling the target application, if the at least one injection has not been de-registered from the injection cache.

20. The media of claim 16 , the processor being operable to perform further operations comprising adding at least one test script, at least one detector script and at least one queue.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2011
From: SCHRECKER, SVEN; ANDREWS, MICHAEL
To: MCAFEE, INC.
Reel/Frame 026528/0419 →