IP Library Granted Patent US 9,838,412
Granted Patent B2
US 9,838,412 · App. 14/928,714 · Granted Dec 5, 2017

Computer software application self-testing

Inventors: Roi Saltzman (Rishon le Zion, IL); Ory Segal (Tel Aviv, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/1433G06F11/368G06F11/3612G06F11/3684G06F21/52G06F21/577H04L63/14G06F11/36G06F11/3636
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,838,412
App. No.
14/928,714
Granted
Dec 5, 2017
Kind
B2
Abstract

Testing a computer software application by detecting an arrival of input data provided as input to a computer software application from a source external to the computer software application, modifying the detected input data to include test data configured to test the computer software application in accordance with a predefined test, thereby creating a modified version of the detected input data, and processing the modified version of the detected input data, thereby performing the predefined test on the computer software application using the test data.

Claims (58)

1. A computer-implemented method for testing a computer software application, comprising:

receiving, by the computer software application, input data from a source external to the computer software application;

modifying, by the computer software application, the received input data to include test data to create a modified version of the received input data; and

performing a predefined test on the computer software application using the test data, wherein

the test data is configured to perform the predefined test.

2. The method of claim 1 , wherein

the computer software application is instructed to perform the modifying.

3. The method of claim 1 , wherein

the computer software application is a web application, and

the received input data is an HTTP request.

4. The method of claim 1 , wherein

the predefined tests is configured to test for a known type of security vulnerability, and

the test data includes a malicious payload configured to exploit the security vulnerability.

5. The method of claim 1 , wherein

the modifying creates a plurality of modified versions of the received input data using, respectively, using different test data.

6. The method of claim 1 , wherein

results of the predefined test are forwarded to the source.

7. The method of claim 6 , wherein

the source is a dynamic analyzer.

8. A computer hardware system configured to test a computer software application, comprising:

at least one processor configured to initiate the following executable operations comprising:

receiving, by the computer software application, input data from a source external to the computer software application;

modifying, by the computer software application, the received input data to include test data to create a modified version of the received input data; and

performing a predefined test on the computer software application using the test data, wherein

the test data is configured to perform the predefined test.

9. The system of claim 8 , wherein

the computer software application is instructed to perform the modifying.

10. The system of claim 8 , wherein

the computer software application is a web application, and

the received input data is an HTTP request.

11. The system of claim 8 , wherein

the predefined tests is configured to test for a known type of security vulnerability, and

the test data includes a malicious payload configured to exploit the security vulnerability.

12. The system of claim 8 , wherein

the modifying creates a plurality of modified versions of the received input data using, respectively, using different test data.

13. The system of claim 8 , wherein

results of the predefined test are forwarded to the source.

14. The system of claim 13 , wherein

the source is a dynamic analyzer.

15. A computer program product, comprising:

a computer-readable storage medium having stored therein computer-readable program code for testing a computer software application

the computer-readable program code, when executed by a computer hardware system, causes the computer hardware system to perform:

receiving, by the computer software application, input data from a source external to the computer software application;

modifying, by the computer software application, the received input data to include test data to create a modified version of the received input data; and

performing a predefined test on the computer software application using the test data, wherein

the test data is configured to perform the predefined test.

16. The computer program product of claim 15 , wherein

the computer software application is instructed to perform the modifying.

17. The computer program product of claim 15 , wherein

the computer software application is a web application, and

the received input data is an HTTP request.

18. The computer program product of claim 15 , wherein

the predefined tests is configured to test for a known type of security vulnerability, and

the test data includes a malicious payload configured to exploit the security vulnerability.

19. The computer program product of claim 15 , wherein

the modifying creates a plurality of modified versions of the received input data using, respectively, using different test data.

20. The computer program product of claim 15 , wherein

results of the predefined test are forwarded to the source.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2018
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: FINJAN BLUE, INC.
Reel/Frame 046037/0040 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2015
From: SALTZMAN, ROI; SEGAL, ORY
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 036927/0104 →
Continuity (2)
Continuation 13602559 · Sep 4, 2012
Related Publication 20160055073A1 · Feb 25, 2016