IP Library Granted Patent US 10,002,254
Granted Patent B2
US 10,002,254 · App. 15/268,503 · Granted Jun 19, 2018

Systems and methods for SQL type evaluation to detect evaluation flaws

Inventors: Kunal Anand (Marina Del Rey, CA); Michael Crampon (Edmonds, WA); Richard Meester (Camarillo, CA); Joseph Rozner (Northridge, CA); Joshua Chase (Los Angeles, CA)
Assignee: PREVOTY, INC.
G06F21/577G06F17/3051G06F17/30371G06F21/52G06F21/566G06F2221/033G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,002,254
App. No.
15/268,503
Granted
Jun 19, 2018
Kind
B2
Abstract

Methods and apparatuses for detecting an evaluation flaw in a SQL query, the SQL query configured to access data in a database table are disclosed. The method includes creating a parse tree from the SQL query and evaluating the parse tree to ascertain whether a condition of the SQL query results in a type or value that is independent of contents of the database table. For type evaluation, if, responsive to the evaluating, the condition is found, designating the SQL query at risk for having the tautology in the SQL query. For value evaluation, if, responsive to the evaluating, the condition is found, determining whether the condition is always true or whether the condition is always false; and if, responsive to the determining, the condition is found to be always true or always false, designating the SQL query at risk for having the evaluation flaw in the SQL query.

Claims (35)

1. A method for detecting a tautology in a SQL query, said SQL query configured to access data in a database table, comprising:

creating a parse tree from said SQL query;

evaluating said parse tree to ascertain whether a condition of said SQL query is a type that is independent of contents of said database table by determining a type of a unary expression and passing the type up to a parent node in the parse tree for further evaluation based upon component types to determine an evaluated expression type, recording the evaluated expression type at a where clause; and

when, responsive to said evaluating, said condition is found, designating said SQL query at risk for having said tautology in said SQL query,

wherein said condition is deemed found when said SQL query involves a comparison between two static types, each of said two static types being independent of contents of said database table and at least one of said two static types being a deterministic function operating on a static type.

2. The method of claim 1 , wherein said evaluating includes a bottom-up evaluation of said parse tree.

3. The method of claim 1 , wherein said condition is a result of a comparison operation.

4. The method of claim 1 , wherein said condition is deemed found when said SQL query involves a comparison between two static types, each of said two static types being independent of contents of said database table.

5. The method of claim 1 , wherein said condition is deemed found when said SQL query involves an operation that always evaluates to be true irrespective of contents of said database table.

6. The method of claim 1 , wherein said evaluating said parse tree further including storing a type of a select list element for subsequent expression evaluation.

7. The method of claim 6 , further comprising performing said subsequent expression evaluation when said select list element is a part of a sub-query.

8. The method of claim 1 , wherein said condition is deemed found when said SQL query involves a comparison between two literals.

9. A method for detecting a tautology in a SQL query, said SQL query configured to access data in a database table, comprising:

creating a parse tree from said SQL query;

evaluating step-wise, using a bottom-up methodology, through said parse tree to ascertain whether a condition of said SQL query results in a type that is independent of contents of said database table by determining a type of a unary expression and passing the type up to a parent node in the parse tree for further evaluation based upon component types to determine an evaluated expression type, recording the evaluated expression type at a where clause; and

when said condition is found, responsive to said evaluating, designating said SQL query at risk for having said tautology in said SQL query,

wherein said condition is deemed found when said SQL query involves a comparison between two static types, each of said two static types being independent of contents of said database table and at least one of said two static types being a deterministic function operating on a static type.

10. The method of claim 9 , wherein said evaluating includes a bottom-up evaluation of said parse tree.

11. The method of claim 9 , wherein said evaluating includes employing a comparison operation.

12. The method of claim 9 , wherein said condition is deemed found when said SQL query involves a comparison between two static types, each of said two static types being independent of contents of said database table.

13. The method of claim 9 , wherein said condition is deemed found when said SQL query involves an operation that always evaluates to be true irrespective of contents of said database table.

14. The method of claim 9 , wherein said evaluating said parse tree further including storing a type of a select list element for subsequent expression evaluation.

15. The method of claim 14 , further comprising performing said subsequent expression evaluation when said select list element is a part of a sub-query.

16. The method of claim 9 , wherein said condition is deemed found when said SQL query involves a comparison between two literals.

17. A method for detecting a tautology in a SQL query, said SQL query configured to access data in a database table, comprising:

creating a parse tree from said SQL query;

evaluating step-wise, using a bottom-up methodology, through said parse tree said parse tree, including:

evaluating a type of a unary expression object;

passing the type up to a parent node in the parse tree for further evaluation based upon component types to determine an evaluated expression type;

recording the evaluated expression type at a where clause;

evaluating a condition for said data access, said condition employing said expression; and

when said condition is satisfied independent of contents of said database table, designating said SQL query at risk for having said tautology in said SQL query,

wherein said condition is deemed found when said SQL query involves a comparison between two static types, each of said two static types being independent of contents of said database table and at least one of said two static types being a deterministic function operating on a static type.

18. The method of claim 17 , wherein said evaluating said expression includes evaluating a comparison operation.

19. The method of claim 17 , wherein said condition is deemed found when said SQL query involves a comparison between two static types, each of said two static types being independent of contents of said database table.

Assignments (7)
RELEASE OF FIRST LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 048077/0753 Recorded Dec 1, 2023
From: BANK OF AMERICA, N.A., AS AGENT
To: PREVOTY, INC.
Reel/Frame 065744/0045 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 048077/0795 Recorded Dec 1, 2023
From: GOLDMAN SACH BANK USA, AS AGENT
To: PREVOTY, INC.
Reel/Frame 065744/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2022
From: PREVOTY, INC.
To: IMPERVA, INC.
Reel/Frame 059786/0372 →
CHANGE OF ASSIGNEE ADDRESS Recorded Feb 23, 2022
From: PREVOTY, INC.
To: PREVOTY, INC.
Reel/Frame 059353/0953 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 15, 2019
From: PREVOTY, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 048077/0753 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 15, 2019
From: PREVOTY, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 048077/0795 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2017
From: ANAND, KUNAL; CRAMPON, MICHAEL; MEESTER, RICHARD; ROZNER, JOSEPH; CHASE, JOSHUA
To: PREVOTY, INC.
Reel/Frame 041001/0402 →
Continuity (4)
Continuation In Part 14599978 · Jan 19, 2015
Provisional Application 62220903 · Sep 18, 2015
Provisional Application 61929474 · Jan 20, 2014
Related Publication 20170068819A1 · Mar 9, 2017
Cited By (2)
US 12,483,597 US 12,518,001