IP Library › Granted Patent US 9,390,270
Granted Patent B2
US 9,390,270 · App. 14/294,294 · Granted Jul 12, 2016

Security testing using semantic modeling

Inventors: Evgeny Beskrovny (Ramat Gan, IL); Alexander Landa (Haifa, IL); Omer Tripp (Bronx, NY)
Assignee: GLOBALFOUNDRIES INC.
G06F21/577H04L63/1433G06F11/3668G06F11/3672H04L41/28
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,390,270
App. No.
14/294,294
Granted
Jul 12, 2016
Kind
B2
Abstract

Optimized testing of vulnerabilities in an application implemented by a method includes generating a first probe directed to determine whether an application is vulnerable to a first type of attack; analyzing one or more responses from the application based on the application responding to the first probe; in response to determining that the one or more responses from the application validate a first hypothesis about one or more vulnerabilities associated with the application, and generating at least a second probe to further verify the first hypothesis. The second probe focuses on discovering additional details about the application's vulnerabilities to the first type of attack or a second type of attack.

Claims (32)

1. A method for optimized testing of vulnerabilities in an application, the method comprising:

performing vulnerability testing on a software application, comprising:

generating a first probe configured to determine whether the software application is vulnerable to a first type of attack, the generating comprising selecting the first probe from a list of tests, and embedding test data in a payload that simulates a particular type of attack on the software application, each of the tests from the list of tests simulating a different type of attack;

inputting the first probe to the software application;

analyzing one or more responses to the first probe received from the software application;

in response to determining that the one or more responses from the software application validate a first hypothesis that one or more vulnerabilities is associated with the software application, generating at least a second probe to further verify the first hypothesis, wherein the second probe is configured to discover additional details about the software application's vulnerabilities to the first type of attack;

inputting the second probe to the software application;

analyzing one or more responses to the second probe received from the software application;

determining an accuracy of the first hypothesis based on results of the analyzing the one or more responses to the second probe, the first hypothesis is determined to be accurate when an attack on the software application, as defined by the payload, is successful in exposing a vulnerability in the software application; and

performing further testing of the software application as a function of the accuracy of the first hypothesis.

2. The method of claim 1 , wherein the one or more responses from the software application based on the software application responding to the second probe are analyzed to determine whether the first hypothesis is accurate within a predetermined degree of certainty.

3. The method of claim 2 , wherein upon determining that the first hypothesis is accurate within the predetermined degree of certainty, the software application is determined to be vulnerable to at least the first type of attack.

4. The method of claim 1 , wherein a test tool is utilized to generate the first probe or the second probe targeting the software application.

5. The method of claim 1 , wherein the application is a web application.

6. The method of claim 2 , wherein upon determining that the first hypothesis is not accurate within the predetermined degree of certainty, discontinuing any further probes for testing the software application with respect to the first type of attack.

7. The method of claim 2 , wherein in response to determining that the one or more responses from the software application do validate the first hypothesis that one or more vulnerabilities is associated with the software application, refraining from generating the second probe.

8. The method of claim 1 , wherein the software application responds to the first probe based on a sanitization process.

9. The method of claim 1 , wherein a probing space for the software application is represented as a graph with a plurality of nodes and edges connecting at least two nodes, where a node in the graph represents a hypothesis about a defense mechanism implemented by the software application, and an edge connecting two nodes in the graph defines a hierarchical relationship between the first hypothesis and a second hypothesis.

10. A computer program product comprising a nontransitory computer readable storage medium having a computer readable program, wherein the computer readable program when executed on a computer causes the computer to:

perform vulnerability testing on a software application, comprising:

generate a first probe configured to determine whether the software application is vulnerable to a first type of attack, the generating comprising selecting the first probe from a list of tests, and embedding test data in a payload that simulates a particular type of attack on the software application, each of the tests from the list of tests simulating a different type of attack;

input the first probe to the software application;

analyze one or more responses to the first probe received from the software application;

in response to determining that the one or more responses from the software application validate a first hypothesis that one or more vulnerabilities is associated with the software application, generate at least a second probe to further verify the first hypothesis, wherein the second probe is configured to discover additional details about the software application's vulnerabilities to the first type of attack;

input the second probe to the software application;

analyze one or more responses to the second probe received from the software application;

determine an accuracy of the first hypothesis based on results of the analyzing the one or more responses to the second probe, the first hypothesis is determined to be accurate when an attack on the software application, as defined by the payload, is successful in exposing a vulnerability in the software application; and

perform further testing of the software application as a function of the accuracy of the first hypothesis.

11. The computer program product of claim 10 , wherein the one or more responses from the software application based on the software application responding to the second probe are analyzed to determine whether the first hypothesis is accurate within a predetermined degree of certainty.

12. The computer program product of claim 11 , wherein upon determining that the first hypothesis is accurate within the predetermined degree of certainty, the software application is determined to be vulnerable to at least the first type of attack.

13. The computer program product of claim 10 , wherein a test tool is utilized to generate the first probe or the second probe targeting the application.

14. The method of claim 1 , wherein the software application responds to the first probe based on a validation process.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded May 12, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES U.S. INC.
Reel/Frame 056987/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 20, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES INC.
Reel/Frame 054636/0001 →
SECURITY AGREEMENT Recorded Nov 29, 2018
From: GLOBALFOUNDRIES INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 049490/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2015
From: GLOBALFOUNDRIES U.S. 2 LLC; GLOBALFOUNDRIES U.S. INC.
To: GLOBALFOUNDRIES INC.
Reel/Frame 036779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2015
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GLOBALFOUNDRIES U.S. 2 LLC
Reel/Frame 036550/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2014
From: BESKROVNY, EVGENY; LANDA, ALEXANDER; TRIPP, OMER
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 033015/0912 →
Continuity (2)
Continuation 14041010 · Sep 30, 2013
Related Publication 20150096036A1 · Apr 2, 2015