IP Library Granted Patent US 9,948,665
Granted Patent B2
US 9,948,665 · App. 14/730,261 · Granted Apr 17, 2018

Persistent cross-site scripting vulnerability detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,948,665
App. No.
14/730,261
Granted
Apr 17, 2018
Kind
B2
Abstract

Various techniques for detecting a persistent cross-site scripting vulnerability are described herein. In one example, a method includes detecting, via the processor, a read operation executed on a resource using an instrumentation mechanism and returning, via the processor, a malicious script in response to the read operation. The method also includes detecting, via the processor, a write operation executed on the resource using the instrumentation mechanism and detecting, via the processor, a script operation executed by the malicious script that results in resource data being sent to an external computing device from a client device. Furthermore, the method includes receiving, via the processor, metadata indicating the execution of the read operation, the write operation, and the script operation.

Claims (11)

1. A method for detecting a persistent cross-site scripting vulnerability comprising:

inserting, via a processor, a client-side script as input into a web application;

requesting, via the processor, data from the web application; in response to requesting the data, detecting that resource is sent from a client device to an external computing device in response to execution of the client-side script on the client device, wherein the external computing device is a different device than the client device;

receiving at the external computing device, the inserted client-side script in response to requesting data from the web application; receiving from the external computing device, the inserted client-side script, in response to receiving the client-side script at the external computing device;

detecting, via the processor, that the client-side script is subsequently returned unaltered via the data request by comparing the inserted client-side script with the received client side script, and that execution of the client-side script occurs.

2. The method of claim 1 , further comprising:

monitoring function calls to one or more resources to detect a write operation attempting to store the inputted client-side script on a resource without alteration.

3. The method of claim 1 , wherein the inserted input simulates user interaction with the web application.

4. The method of claim 1 , further comprising, responsive to detecting that execution of the client-side script occurred, creating an indicator of a cross-site scripting vulnerability found in the web application.

5. The method of claim 1 , wherein the inserted client-side script contains instructions to send an alert when executed.

6. The method of claim 5 , wherein detecting whether execution of the client-side script occurs comprises receiving the alert.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: HCL TECHNOLOGIES LIMITED
Reel/Frame 050374/0781 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2015
From: BRONSHTEIN, EMANUEL; HAY, ROEE; KEDMI, SAGI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 035782/0848 →