IP Library Granted Patent US 9,781,145
Granted Patent B2
US 9,781,145 · App. 14/552,570 · Granted Oct 3, 2017

Persistent cross-site scripting vulnerability detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,781,145
App. No.
14/552,570
Granted
Oct 3, 2017
Kind
B2
Abstract

A system and program product are described herein for various techniques for detecting a persistent cross-site scripting vulnerability are described herein. In one example, the techniques include detecting, via the processor, a read operation executed on a resource using an instrumentation mechanism and returning, via the processor, a malicious script in response to the read operation. The techniques also include detecting, via the processor, a write operation executed on the resource using the instrumentation mechanism and detecting, via the processor, a script operation executed by the malicious script that results in resource data being sent to an external computing device from a client device. Furthermore, the techniques include receiving, via the processor, metadata indicating the execution of the read operation, the write operation, and the script operation.

Claims (24)

1. A system for detecting a persistent cross-site scripting vulnerability comprising:

a memory device comprising processor executable instructions; and

a processor, the processor executable instructions including instructions to:

insert a client-side script as input into a web application;

request data from the web application;

in response to the data request, detect that resource data from a client device is sent to an external computing device in response to execution of the client-side script on the client device, wherein the external computing device is a different device than the client device;

receive at the external computing device, the inserted client-side script in response to requesting data from the web;

receive from the external computing device, the inserted client-side script, in response to receiving the client-side script at the external computing device;

detect that the client-side script is subsequently returned unaltered via the data request by comparing the inserted client-side script with the received client-side script, and that execution of the client-side script occurs.

2. The system of claim 1 , wherein the inserted input simulates user interaction with the web applications.

3. The system of claim 1 , wherein the processor executable instructions further include instructions to, responsive to detecting that execution of the client-side script occurred, create an indicator of a cross-site scripting vulnerability in the web applications, the indicator including metadata comprising at least one of: call stack data, a test identifier, a read bit, a write bit, and a script bit.

4. A computer program product for detecting a persistent cross-site scripting vulnerability, the computer program product comprising:

one or more non-transitory computer readable storage media;

program instructions stored on the one or more non-transitory computer readable storage media, executable by a processing circuit, the program instructions comprising:

program instructions to insert a client-side script as input into a web application;

program instructions to request data from the web application; and

in response to the data request, program instructions to detect that resource data from a client device is sent to an external computing device in response to execution of the client-side script on the client device, wherein the external computing device is a different device than the client device;

program instructions to receive at the external computing device, the inserted client-side script in response to requesting data from the web;

program instructions to receive from the external computing device, the inserted client-side script, in response to receiving the client-side script at the external computing device;

program instructions to detect that the inserted client-side script is subsequently returned unaltered via the data request by comparing the inserted client-side script with the received client-side script, and that execution of the client-side script occurs.

5. The computer program product of claim 4 , wherein the program instructions further comprise:

program instructions to monitor function calls to one or more resources to detect a write operation attempting to store the inputted client-side script on a resource without.

6. The computer program product of claim 4 , wherein the program instructions further comprise program instructions to detect whether resource data from a client device is sent to an external computing device in response to execution of the client-side script on the client device.

7. The computer program product of claim 4 , wherein the inserted input simulates user interaction with the web application.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: HCL TECHNOLOGIES LIMITED
Reel/Frame 050374/0781 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2015
From: BRONSHTEIN, EMANUEL; HAY, ROEE; KEDMI, SAGI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 034698/0367 →