IP Library Granted Patent US 8,863,280
Granted Patent B1
US 8,863,280 · App. 13/732,554 · Granted Oct 14, 2014

Automatic response culling for web application security scan spidering process

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,863,280
App. No.
13/732,554
Granted
Oct 14, 2014
Kind
B1
Abstract

A method of testing a web application, wherein a web application is a program that operates on a server and interacts with clients that access the program over a network, wherein further the web application accepts parameters that define results generated from the web application, the method comprising determining which web application uniform resource identifiers (URIs) are used to access various web applications on a system, determining if more than a threshold of the URIs are for a common web application, selecting a subset of less than all of the URIs for the common web application when the threshold is exceeded for that common web application, wherein the subset is selected at least in part independently of the order generated and performing a security scan on the selected subset.

Claims (36)

1. A method of testing a web application, wherein the web application is a program that operates on a server and interacts with clients that access the program over a network, the method comprising:

identifying the web application, the web application being operable to accept parameters that define responses generated from the web application to the clients;

identifying references to the web application;

selecting a subset of less than all of the references to the web application, wherein selecting

the subset includes culling the identified references based on the parameters; and performing a security scan on the selected subset; and

wherein selecting the subset is based on a random or semi-random skipping of the references as presented in an original identified order.

2. The method of claim 1 , wherein selecting the subset further includes:

identifying requests that are directed to the web application;

identifying parameters being valid for each identified request;

determining the subset to be scanned based on the identified requests or the identified parameters; and

ignoring additional references to the web application when a number of the subset to be scanned reaches a threshold number.

3. The method of claim 1 , wherein the performing the security scan includes scanning the web application for vulnerabilities.

4. The method of claim 1 , wherein the performing the security scan on the selected subset further includes executing at least one electronic interaction with the web application.

5. The method of claim 4 , wherein the at least one electronic interaction includes sending client requests from a testing computer to the web application and evaluating web application responses.

6. The method of claim 1 , wherein the culling includes culling a variable number of references.

7. The method of claim 1 , wherein the culling includes culling the references to the web application when a number of the references is determined as being excessive.

8. The method of claim 1 , further comprising repeating the culling of the identified references until the selected subset is of a size or consistency determined to be useful for the security scanning.

9. A computing device for testing a web application, wherein the web application is a program that operates on a server and interacts with clients that access the program over a network, the computing device comprising:

a computer processor configured to read machine-readable instructions from a tangible, non-transitory computer-readable medium:

the machine-readable instructions comprising:

(a) program code for identifying the web application, the web application being operable to accept parameters that define responses generated from the web application to the clients;

(b) program code for identifying references to the web application;

(c) program code for selecting a subset of less than all of the references to the web application, wherein selecting the subset includes culling the identified references based on the parameters;

(d) program code for performing a security scan on the selected subset; and

wherein selecting the subset is based on a random or semi-random skipping of the references as presented in an original identified order.

10. The computing device of claim 9 , wherein selecting the subset further includes:

identifying requests that are directed to the web application;

identifying parameters being valid for each identified request;

determining the subset to be scanned based on the identified requests and/oror the identified parameters; and

ignoring additional references to the web application when a number of the subset to be scanned reaches a threshold number.

11. The computing device of claim 9 , wherein the performing the security scan includes scanning the web application for vulnerabilities.

12. The computing device of claim 9 , wherein the performing the security scan on the selected subset further includes executing at least one electronic interaction with the web application.

13. The computing device of claim 12 , wherein the at least one electronic interaction includes sending client requests from a testing computer to the web application and evaluating web application responses.

14. The computing device of claim 9 , wherein the culling includes culling a variable number of references.

15. The computing device of claim 9 , wherein the culling includes culling the references to the web application when a number of the references is determined as being excessive.

16. The computing device of claim 9 , further comprising repeating the culling of the identified references until the selected subset is of a size or consistency determined to be useful for the security scanning.

Assignments (11)
SECURITY INTEREST Recorded Sep 30, 2024
From: BLACK DUCK SOFTWARE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 069083/0149 →
CHANGE OF NAME Recorded Jul 30, 2024
From: SOFTWARE INTEGRITY GROUP, INC.
To: BLACK DUCK SOFTWARE, INC.
Reel/Frame 068191/0490 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2024
From: SYNOPSYS, INC.
To: SOFTWARE INTEGRITY GROUP, INC.
Reel/Frame 066664/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2022
From: SYNOPSYS SOFTWARE INTEGRITY SOLUTIONS, INC.
To: SYNOPSYS, INC.
Reel/Frame 060698/0193 →
CHANGE OF NAME Recorded Jul 25, 2022
From: NTT SECURITY APPSEC SOLUTIONS INC.
To: SYNOPSYS SOFTWARE INTEGRITY SOLUTIONS, INC.
Reel/Frame 060884/0443 →
CHANGE OF NAME Recorded Jul 22, 2022
From: WHITEHAT SECURITY, INC.
To: NTT SECURITY APPSEC SOLUTIONS INC.
Reel/Frame 060829/0937 →
RELEASE OF SECURITY INTEREST Recorded Jun 17, 2022
From: ORIX GROWTH CAPITAL, LLC
To: WHITEHAT SECURITY, INC.
Reel/Frame 060242/0589 →
REASSIGNMENT AND RELEASE OF SECURITY INTEREST Recorded Jun 17, 2022
From: WESTERN ALLIANCE BANK AS SUCCESSOR IN INTEREST TO BRIDGE BANK, NATIONAL ASSOCIATION
To: WHITEHAT SECURITY, INC.
Reel/Frame 060456/0685 →
SECURITY INTEREST Recorded Nov 23, 2016
From: WHITEHAT SECURITY, INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 040413/0127 →
SECURITY INTEREST Recorded Sep 29, 2015
From: WHITEHAT SECURITY, INC.
To: BRIDGE BANK, NATIONAL ASSOCIATION
Reel/Frame 036674/0320 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2013
From: PENNINGTON, WILLIAM; GROSSMAN, JEREMIAH; STONE, ROBERT; PAZIRANDEN, SIAMAK
To: WHITEHAT SECURITY, INC.
Reel/Frame 030340/0486 →