IP Library Granted Patent US 9,124,624
Granted Patent B2
US 9,124,624 · App. 13/440,416 · Granted Sep 1, 2015

Detecting vulnerabilities in web applications

Inventors: Yair Amit (Hertzelyia, IL); Daniel Kalman (Hertzelyia, IL); Omer Tripp (Hertzelyia, IL)
Assignee: International Business Machines Corporation
H04L63/1433H04L67/02H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,124,624
App. No.
13/440,416
Granted
Sep 1, 2015
Kind
B2
Abstract

A method, computer program product, and system for detecting vulnerabilities in web applications is described. A method may comprise determining one or more values associated with a web application that flow to response data associated with the web application. The one or more values may be modifiable by unreliable input. The method may further comprise generating a representation of the response data associated with the web application. The method may additionally comprise determining one or more potentially vulnerable portions of the response data based upon, at least in part, the one or more values modifiable by the unreliable input that flow to the response data associated with the web application, and the representation of the response data associated with the web application.

Claims (21)

1. A method comprising:

determining, via one or more computing devices, one or more values associated with a web application that flow to response data associated with the web application, wherein the one or more values are modifiable by unreliable input, wherein the one or more values modifiable by the unreliable input that flow to the response data associated with the web application are determined via, at least in part, a server-side taint analysis algorithm;

determining whether there is a path reaching a statement that renders data to the response data;

marking a value of the one or more values flowing into the response data as untrusted in response to determining that there is a path reaching the statement that renders data to the response data;

generating, via the one or more computing devices, an abstract representation of the response data associated with the web application generated via, at least in part, a string analysis algorithm that approximates at least one of a string output of the response data associated with the web application with a context-free grammar and a logical formula; and

determining, via the one or more computing devices, one or more potentially vulnerable portions of the response data based upon, at least in part, the one or more values modifiable by the unreliable input that flow to the response data associated with the web application, the abstract representation of the response data associated with the web application, and a taint analysis algorithm operating on the abstract representation of the response data.

2. The method of claim 1 , further comprising:

transmitting an indication of the one or more potentially vulnerable portions of the response data to a user computing device configured to receive the response data.

3. The method of claim 1 , wherein the abstract representation of the response data associated with the web application is generated via, at least in part, a string analysis algorithm.

4. The method of claim 1 , wherein the response data corresponds to response HTML associated with the web application.

5. The method of claim 4 , wherein the abstract representation of the response data associated with the web application includes any possible response HTML from the web application.

6. The method of claim 4 , wherein the one or more potentially vulnerable portions of the response data are one or more portions of a document object model associated with the response HTML that corresponds to the response data.

7. The method of claim 6 , further comprising:

determining whether unreliable input has flown to the response HTML that corresponds to the response data and compromised security of the web application.

8. A method comprising:

receiving, at a user computing device, an indication of one or more potentially vulnerable portions of a document object model associated with a response HTML from a web application, the indication based upon, at least in part:

one or more values modifiable by unreliable input that flows to the response HTML and are determined, at least in part, by a first taint analysis algorithm, wherein the first taint analysis algorithm is a server-side taint analysis algorithm;

determining whether there is a path reaching a statement that renders data to the response data;

marking a value of the one or more values flowing into the response data as untrusted in response to determining that there is a path reaching the statement that renders data to the response data; and

an abstract representation of the response HTML generated, at least in part, by a string analysis algorithm that approximates at least one of a string output of the response data associated with the web application with a context-free grammar and a logical formula; and

determining, via the user computing device, whether unreliable input has flown to the response HTML and compromised security of the web application by running a second taint analysis algorithm informed by the indication of one or more potentially vulnerable portions of the document object model associated with the response HTML from the web application, wherein the second taint analysis algorithm is a taint analysis algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2018
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: FINJAN BLUE, INC.
Reel/Frame 046037/0040 →
Continuity (2)
Continuation 13307780 · Nov 30, 2011
Related Publication 20130139267A1 · May 30, 2013