IP Library Granted Patent US 8,695,098
Granted Patent B2
US 8,695,098 · App. 13/174,628 · Granted Apr 8, 2014

Detecting security vulnerabilities in web applications

Inventors: Marco Pistoia (New York, NY); Ori Segal (Tel Aviv, IL); Omer Tripp (Har-Adar, IL)
Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,695,098
App. No.
13/174,628
Granted
Apr 8, 2014
Kind
B2
Abstract

Method to detect security vulnerabilities includes: interacting with a web application during its execution to identify a web page exposed by the web application; statically analyzing the web page to identify a parameter within the web page that is constrained by a client-side validation measure and that is to be sent to the web application; determining a server-side validation measure to be applied to the parameter in view of the constraint placed upon the parameter by the client-side validation measure; statically analyzing the web application to identify a location within the web application where the parameter is input into the web application; determining whether the parameter is constrained by the server-side validation measure prior to the parameter being used in a security-sensitive operation; and identifying the parameter as a security vulnerability.

Claims (22)

1. A system comprising:

a black-box tester comprising a hardware processor configured to interact with a web application during its execution to identify a web page exposed by the web application, the web application being hosted by a server and accessible by a client computer;

a constraint manager configured to:

receive the web page identified by the black-box tester;

statically analyze the web page to identify a hidden parameter within the web page that is constrained by a client-side validation measure and that is to be sent to the web application, the hidden parameter to indicate an authorization level of a user of the client computer; and

determine a server-side validation measure to be applied to the hidden parameter comprising the web application checking for a correlation between a value of the hidden parameter and a value of at least one other parameter from the user; and

a static analyzer configured to:

statically analyze the web application to identify a location within the web application where the hidden parameter is input into the web application;

query the constraint manager for the server-side validation measure to be applied to the hidden parameter;

determine whether the web application checks for the correlation between the value of the hidden parameter and the value of the least one other client-supplied parameter according to the server-side validation measure from the constraint manager prior to the hidden parameter being used in a security-sensitive operation; and

identify the hidden parameter as a security vulnerability where the web application does not check for the correlation between the value of the hidden parameter and the value of the at least one other client-supplied parameter prior to the hidden parameter being used in the security-sensitive operation.

2. The system of claim 1 wherein the static analyzer is further configured to statically analyze the web application by building a control-flow model and a data-flow model of the web application.

3. A computer program product comprising:

a non-transitory computer readable storage medium; and

computer-readable program code stored in the computer-readable storage medium, where the computer-readable program code is configured to:

interact with a web application during its execution to identify a web page exposed by the web application, the web application being hosted by a server and accessible by a client computer;

statically analyze the web page to identify a hidden parameter within the web page that is constrained by a client-side validation measure and that is to be sent to the web application, the hidden parameter to indicate an authorization level of a user of the client computer;

determine a server-side validation measure to be applied to the hidden parameter comprising the web application checking for a correlation between a value of the hidden parameter and a value of at least one other parameter from the user;

statically analyze the web application to identify a location within the web application where the hidden parameter is input into the web application;

determine whether the web application checks for the correlation between the value of the hidden parameter and the value of the least one other client-supplied parameter according to the server-side validation measure prior to the hidden parameter being used in a security-sensitive operation; and

identify the hidden parameter as a security vulnerability where the web application does not check for the correlation between the value of the hidden parameter and the value of the at least one other client-supplied parameter prior to the hidden parameter being used in the security-sensitive operation.

4. The computer program product of claim 3 wherein the computer-readable program code is further configured to build a control-flow model and a data-flow model of the web application.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2018
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: FINJAN BLUE, INC.
Reel/Frame 046037/0040 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2011
From: PISTOIA, MARCO; SEGAL, ORI; TRIPP, OMER
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 026533/0281 →
Continuity (1)
Related Publication 20130007886A1 · Jan 3, 2013