IP Library Granted Patent US 9,215,247
Granted Patent B2
US 9,215,247 · App. 14/116,000 · Granted Dec 15, 2015

Application security testing

Inventors: Brian V. Chess (Palo Alto, CA); Iftach Ragoler (Alpharetta, GA); Philip Edward Hamer (Alpharetta, GA); Russell Andrew Spitler (San Francisco, CA); Sean Patrick Fay (San Francisco, CA); Prajakta Subbash Jagdate (Alpharetta, GA)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/1433G06F11/0727G06F11/0793G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,215,247
App. No.
14/116,000
Granted
Dec 15, 2015
Kind
B2
Abstract

The present disclosure provides a system that includes a server hosting an application under test (AUT), an observer configured to monitor instructions executed by the AUT, and a computing device communicatively coupled to the AUT and the observer through a common communication channel. The computing device may be configured to send an application request to the AUT, wherein the application request is configured to expose a potential vulnerability of the AUT. The computing device may receive an application response from the AUT in accordance with the AUT's programming. The computing device may send a service request to the observer, and receive a service response from the observer that contains information corresponding to the instructions executed by the AUT due to the application request, information about the AUT, or information about a server hosting the AUT.

Claims (52)

1. A system, comprising:

a server hosting an application under test (AUT);

an observer configured to i) monitor instructions executed by the AUT, ii) generate a trace identifying instructions executed by the AUT as a result of an application request, and iii) send the trace to a requesting computing device in a body of a service response; and

a computing device communicatively coupled to the AUT and the observer through a common communication channel, the computing device comprising a processor and a memory device for storing computer-readable instructions configured to direct the processor to:

send the application request to the AUT, wherein the application request is configured to expose a potential vulnerability of the AUT;

receive an application response from the AUT in accordance with the AUT's programming;

send a service request to the observer; and

receive the service response from the observer, the service response containing information corresponding to the instructions executed by the AUT due to the application request, information about the AUT, or information about a server hosting the AUT.

2. The system of claim 1 , wherein the observer is configured to communicate with the computing device, at least in part, by adding a custom header to the application response.

3. The system of claim 1 , the memory device comprising computer-readable instructions configured to direct the processor to receive trace information from the observer, the trace information comprising a plurality of vulnerability trace nodes, each vulnerability trace node containing code locations corresponding to a vulnerability detected by the observer.

4. The system of claim 3 , the memory device comprising computer-readable instructions configured to direct the processor to group the plurality of vulnerability trace nodes based on the vulnerability trace nodes containing the same code locations.

5. The system of claim 1 , wherein the observer is configured to monitor the AUT to identify new uniform resource locators (URLs) that are generated dynamically during runtime of the ALT, and return an update field in a header of the application response, the update field configured to inform the computing device that an attack surface of the AUT has changed.

6. The system of claim 1 , wherein the observer is configured to:

receive a request from the computing device and analyze a header of the request;

identify the request as the application request or the service request based on the analysis of the header;

pass the application request to the AUT; and

process the service request without passing the service request to the AUT.

7. A method, comprising:

sending an application request to an application under test (AUT), wherein the application request is configured to expose a potential vulnerability of the AUT;

receiving an application response from the AUT in accordance with the AUT's programming;

sending a service request to an observer that i) monitors instructions executed by the AUT, ii) generates a trace identifying instructions executed by the AUT as a result of the application request, and iii) sends the trace in a body of a service response; and

receiving the service response from the observer, the service response containing information corresponding to instructions executed by the AUT due to the application request, information about the AUT, or information about a server hosting the AUT;

wherein the application request, application response, service request, and service response are communicated over a same network channel.

8. The method of claim 7 , comprising receiving a file-not-found header in the application response, the file-not-found header added to the application response by the observer to indicate a file-not-found error generated by the AUT.

9. The method of claim 7 , wherein the service request is a trace service request, the method comprising receiving a stack trace in a body of the service response received from the observer,

10. The method of claim 7 , comprising receiving a vulnerability trace node in the body of the service response, wherein the vulnerability trace node identifies a vulnerability detected by the observer.

11. The method of claim 7 , wherein the service request is an attack surface service request, the method comprising receiving information about the attack surface of the AUT in a body of the service response, the attack surface comprising static URLs and dynamic URLs that are generated by the AUT during runtime.

12. The method of claim 7 , further comprising:

communicating, by the observer, by adding a custom header to the application response.

13. The method of claim 7 , further comprising:

receiving, by the observer, a request and analyzes a header of the request;

identifying, by the observer, the request as the application request or the service request based on the analysis of the header;

passing, by the observer, the application request to the AUT; and

processing, by the observer, the service request without passing the service request to the AUT.

14. The method of claim 7 , wherein the trace includes trace information comprising a plurality of vulnerability trace nodes, each vulnerability trace node containing code locations corresponding to a vulnerability detected by the observer.

15. A non-transitory, compute le medium, comprising code configured to direct a processor to:

send an application request to an application under test (AUT), wherein the application request is configured to expose a potential vulnerability of the AUT;

receive an application response from the AUT in accordance with the ALT's programming;

send a service request to an observer that i) monitors instructions executed by the AUT, ii) generates a trace identifying instructions executed by the AUT as a result of the application request, and iii) sends the trace in a body of a service response; and

receive the service response from the observer, the service response containing information corresponding to instructions executed by the AUT due to the application request, information about the AUT, or information about a server hosting the AUT;

wherein the application request, application response, service request, and service response are communicated over a same network channel.

16. The non-transitory, computer readable medium of claim 15 , comprising code configured to direct the processor to add a request ID to a header of the application request that uniquely identifies the application request, wherein the service response received from the observer includes the request ID.

17. The non-transitory, computer readable medium of claim 15 , wherein the service response includes a database trace node that includes information corresponding to a database query performed by the AUT as a result of the application request.

18. The non-transitory, computer readable medium of claim 15 , wherein the observer communicates, at least in part, by adding a custom header to the application response.

19. The non-transitory, computer readable medium of claim 15 , wherein the observer:

receives a request and analyzes a header of the request;

identifies the request as the application request or the service request based on the analysis of the header;

passes the application request to the AUT; and

processes the service request without passing the service request to the AUT.

20. The non-transitory, computer readable medium of claim 15 , wherein:

the service request is an attack surface service request, and

information about the attack surface of the AUT is included in the body of the service response, and the attack surface comprises static URLs and dynamic URLs that are generated by the AUT during runtime.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2014
From: CHESS, BRIAN V; RAGOLER, IFTACH; HAMER, PHILIP EDWARD; SPITLER, RUSSELL ANDREW; FAY, SEAN PATRICK; JAGDALE, PRAJAKTA
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 031893/0825 →
Continuity (1)
Related Publication 20140082739A1 · Mar 20, 2014