IP Library Granted Patent US 9,736,177
Granted Patent B2
US 9,736,177 · App. 15/003,262 · Granted Aug 15, 2017

Automated security testing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,736,177
App. No.
15/003,262
Granted
Aug 15, 2017
Kind
B2
Abstract

A method of automated security testing includes recording a macro. The recorded macro is played and a web request is intercepted while playing the macro. The web request may be attacked and sent to a web server. A response from the web server based on the web request is received, and the response of the web server is processed to determine any vulnerabilities.

Claims (39)

1. A non-transitory machine-readable storage medium encoded with instructions executable by a processor of a computing device, the non-transitory machine-readable storage medium comprising instructions to:

intercept a web request from a web browser while playing a recorded macro, wherein the macro comprises a series of actions related to a web page;

attack the web request;

send the web request to a webserver; and

process a response of the web server based on the web request to determine any vulnerabilities.

2. The non-transitory machine-readable storage medium of claim 1 , further comprising instructions to determine, in response to executing a script within the web browser, vulnerabilities based on the document object model hooked to application code of the script.

3. The non-transitory machine-readable storage medium of claim 1 , further comprising instructions to inject malicious code into the web request.

4. The non-transitory machine-readable storage medium of claim 1 , further comprising instructions to record a macro by recording a user's interactions with the web browser.

5. The non-transitory machine-readable storage medium of claim 1 , further comprising instructions to record a macro by finding an element of the document object model after the document object model has been changed based on the element's location relative to at least one of other elements in the document object model, a tag name, an element ID, or an element name.

6. The non-transitory machine-readable storage medium of claim 1 , further comprising instructions to record a macro by defining an element for recording, wherein the element is indicative of a logged out, a logged in state, or a set of questions and answers.

7. The non-transitory machine-readable storage medium of claim 1 , further comprising instructions to record a macro by recording an element of a web page using an event handler.

8. The non-transitory machine-readable storage medium of claim 1 , further comprising instructions to attack the web request while playing the recorded macro.

9. The non-transitory machine-readable storage medium of claim 1 , wherein the web request is sent to the web server that is an original destination of the web request before it is intercepted.

10. The non-transitory machine-readable storage medium of claim 1 , further comprising instructions to add a corresponding rule as to what constitutes a vulnerability to the web request.

11. A non-transitory machine-readable storage medium encoded with instructions executable by a processor of a computing device, the non-transitory machine-readable storage medium comprising instructions to:

intercept a web request from a web browser while playing a recorded macro, wherein the macro comprises a series of actions related to a web page;

inject malicious code into the web request;

send the web request to a webserver; and

process a response of the web server based on the web request to determine any vulnerabilities.

12. The non-transitory machine-readable storage medium of claim 11 , further comprising instructions to determine, in response to executing a script within the web browser, vulnerabilities based on the document object model hooked to application code of the script.

13. The non-transitory machine-readable storage medium of claim 11 , wherein the web request is sent to the web server that is an original destination of the web request before it is intercepted.

14. The non-transitory machine-readable storage medium of claim 11 , further comprising instructions to add a corresponding rule as to what constitutes a vulnerability to the web request.

15. The non-transitory machine-readable storage medium of claim 11 , wherein the macro is recorded by at least one of:

recording a user's interactions with the web browser;

finding an element of the document object model after the document object model has been changed based on the element's location relative to at least one of other elements in the document object model, a tag name, an element ID, or an element name;

defining an element for recording, wherein the element is indicative of a logged out, a logged in state, or a set of questions and answers; or

recording an element of a web page using an event handler.

16. A method for execution by a computing device for generating attributes for changing an outcome of a predictive model, comprising:

intercepting a web request from a web browser while playing a recorded macro, wherein the macro comprises a series of actions related to a web page;

injecting, into the web request, malicious code and a corresponding rule as to what constitutes a vulnerability;

sending the web request to a webserver; and

processing a response of the web server based on the web request to determine any vulnerabilities.

17. The method of claim 16 , further comprising determining, in response to executing a script within the web browser, vulnerabilities based on the document object model hooked to application code of the script.

18. The method of claim 16 , wherein the web request is sent to the web server that is an original destination of the web request before it is intercepted.

19. The method of claim 16 , further comprising recording the macro by at least one of:

recording a user's interactions with the web browser;

finding an element of the document object model after the document object model has been changed based on the element's location relative to at least one of other elements in the document object model, a tag name, an element ID, and an element name;

defining an element for recording, wherein the element is indicative of a logged out, a logged in state, or a set of questions and answers; or

recording an element of a web page using an event handler.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2016
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 039297/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2016
From: SIMPSON, SHAWN MORGAN; HAMER, PHILIP EDWARD
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 039115/0242 →