IP Library Granted Patent US 9,460,291
Granted Patent B2
US 9,460,291 · App. 13/429,993 · Granted Oct 4, 2016

Detecting stored cross-site scripting vulnerabilities in web applications

Inventors: Yair Amit (Tel-Aviv, IL); Alexander Landa (Haifa, IL); Omer Tripp (Herzliya, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/577H04L63/1441H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,460,291
App. No.
13/429,993
Granted
Oct 4, 2016
Kind
B2
Abstract

A method for detecting security vulnerabilities in web applications can include providing a payload to a web application during a first interaction with the web application at a computer server, where the payload includes a payload instruction and an identifier, detecting the identifier within the payload received during an interaction with the web application subsequent to the first interaction, and determining, responsive to detecting the identifier within the payload, whether the payload instruction underwent a security check prior to execution of the payload instruction.

Claims (31)

1. A method for detecting security vulnerabilities in web applications, the method comprising:

providing a payload to a web application during a first interaction with the web application at a computer server, where the payload includes a payload instruction and an identifier;

detecting the identifier within the payload received during an interaction with the web application subsequent to the first interaction;

determining, responsive to detecting the identifier within the payload, whether the payload instruction underwent a security check prior to execution of the payload instruction; and

reporting that the web application is vulnerable to a stored cross-site scripting attack where the identifier is detected within the payload and where the payload instruction did not undergo a security check prior to the execution of the payload instruction.

2. The method of claim 1 and further comprising:

receiving an interaction-initiating instruction from the web application during a second interaction with the web application subsequent to the first interaction;

receiving the payload during a third interaction with the web application subsequent to the second interaction; and

executing the interaction-initiating instruction, thereby initiating the third interaction with the web application.

3. The method of claim 2 where

the executing step comprises executing an AJAX request.

4. The method of claim 1 where

the determining step comprises determining whether the payload instruction underwent the security check by being processed by either of a sanitizer and a validator.

5. The method of claim 1 where

the determining step comprises determining whether the payload instruction underwent the security check where the payload instruction is a predefined security-sensitive instruction.

6. The method of claim 5 where

the determining step comprises determining where the security-sensitive instruction is a DOM API command.

7. The method of claim 1 and further comprising

reporting that a vulnerability exists at an interface of the web application through which the payload was introduced.

8. The method of claim 1 and further comprising

reporting that a vulnerability exists at a location within the payload at which the payload instruction is found.

9. A method for detecting security vulnerabilities in web applications, the method comprising:

providing a payload to a web application during a first interaction with the web application at a computer server, where the payload includes a payload instruction and an identifier;

receiving an interaction-initiating instruction from the web application during a second interaction with the web application subsequent to the first interaction;

receiving the payload during a third interaction with the web application subsequent to the second interaction;

executing the interaction-initiating instruction, thereby initiating the third interaction with the web application;

detecting the identifier within the payload received during the third interaction;

determining, responsive to detecting the identifier within the payload, whether the payload instruction underwent a security check prior to execution of the payload instruction; and

reporting that the web application is vulnerable to a stored cross-site scripting attack where the identifier is detected within the payload and where the payload instruction did not undergo a security check prior to the execution of the payload instruction.

10. The method of claim 9 where

the determining step comprises determining whether the payload instruction underwent the security check where the payload instruction is a predefined security-sensitive instruction.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2018
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: FINJAN BLUE, INC.
Reel/Frame 046037/0040 →
Continuity (2)
Continuation 13217418 · Aug 25, 2011
Related Publication 20130055402A1 · Feb 28, 2013