IP Library Granted Patent US 8,910,291
Granted Patent B2
US 8,910,291 · App. 13/430,013 · Granted Dec 9, 2014

Black-box testing of web applications with client-side code evaluation

Inventors: Yinnon A. Haviv (Beerotaim, IL); Daniel Kalman (Herzliya, IL); Dmitri Pikus (Herzliya, IL); Omer Tripp (Herzliya, IL); Omri Weisman (Herzliya, IL)
Assignee: International Business Machines Corporation
G06F21/577H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,910,291
App. No.
13/430,013
Granted
Dec 9, 2014
Kind
B2
Abstract

Detecting security vulnerabilities in web applications by interacting with a web application at a computer server during its execution at the computer server, identifying client-side instructions provided by the web application responsive to an interaction with the web application, where the client-side instructions are configured to be implemented by a client computer that receives the client-side instructions from the computer server, evaluating the identified client-side instructions, and identifying a security vulnerability associated with the client-side instructions.

Claims (16)

1. A method for detecting security vulnerabilities in web applications, the method comprising:

interacting with a web application at a computer server during its execution at the computer server;

identifying client-side instructions provided by the web application responsive to an interaction with the web application, where the client-side instructions are configured to be implemented by a client computer that receives the client-side instructions from the computer server;

evaluating the client-side instructions, and

identifying a security vulnerability associated with the client-side instructions.

2. The method of claim 1 and further comprising identifying a security vulnerability associated with the web application.

3. The method of claim 1 where the evaluating step comprises performing static analysis of the client-side instructions to identify the security vulnerability associated with the client-side instructions.

4. The method of claim 1 where the evaluating step comprises performing dynamic taint analysis on the client-side instructions to track taint propagation within the client-side instructions, thereby identifying the security vulnerability associated with the client-side instructions.

5. The method of claim 4 and further comprising modifying the client-side instructions to store information indicating whether variables within the client-side instructions point to tainted objects, and

where the evaluating step comprises performing dynamic taint analysis on the modified client-side instructions to track taint propagation within the modified client-side instructions, thereby identifying the security vulnerability associated with the client-side instructions.

6. The method of claim 4 where the evaluating step comprises using a predefined security specification to determine which objects within the client-side instructions are tainted and how taint propagates from variable to variable within the client-side instructions.

7. The method of claim 4 where the evaluating step comprises performing dynamic taint analysis on the client-side instructions by calling an interpreter, that is configured to track any variable within the client-side instructions that directly points to a tainted object within the client-side instructions, to track taint propagation within the client-side instructions, thereby identifying the security vulnerability associated with the client-side instructions.

8. The method of claim 7 where the evaluating step comprises performing dynamic taint analysis where the interpreter is configured to track any variable that ultimately depends from any variable within the client-side instructions that directly points to a tainted object within the client-side instructions.

9. The method of claim 7 where the evaluating step comprises performing dynamic taint analysis where the interpreter is configured to use a predefined security specification to determine which objects within the client-side instructions are tainted and how taint propagates from variable to variable within the client-side instructions.

10. The method of claim 4 and further comprising performing symbolic analysis of the client-side instructions to determine at least one value for at least one variable within the client-side instructions that would result in a control flow target being reached within the client-side instructions during execution of the client-side instructions,

where the evaluating step comprises using any value determined by the symbolic analyzer when performing the dynamic taint analysis on the client-side instructions to cause the target control flow.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2018
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: FINJAN BLUE, INC.
Reel/Frame 046037/0040 →
Continuity (2)
Continuation 13170839 · Jun 28, 2011
Related Publication 20130007887A1 · Jan 3, 2013