IP Library Granted Patent US 10,025,936
Granted Patent B2
US 10,025,936 · App. 15/268,510 · Granted Jul 17, 2018

Systems and methods for SQL value evaluation to detect evaluation flaws

Inventors: Kunal Anand (Marina Del Rey, CA); Michael Crampon (Edmonds, WA); Richard Meester (Camarillo, CA); Joseph Rozner (Northridge, CA); Joshua Chase (Los Angeles, CA)
Assignee: PREVOTY, INC.
G06F21/577G06F17/3051G06F17/30371G06F21/52G06F21/566G06F2221/033G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,025,936
App. No.
15/268,510
Granted
Jul 17, 2018
Kind
B2
Abstract

Methods and apparatuses for detecting an evaluation flaw in a SQL query, the SQL query configured to access data in a database table are disclosed. The method includes creating a parse tree from the SQL query and evaluating the parse tree to ascertain whether a condition of the SQL query results in a type or value that is independent of contents of the database table. For type evaluation, if, responsive to the evaluating, the condition is found, designating the SQL query at risk for having the tautology in the SQL query. For value evaluation, if, responsive to the evaluating, the condition is found, determining whether the condition is always true or whether the condition is always false; and if, responsive to the determining, the condition is found to be always true or always false, designating the SQL query at risk for having the evaluation flaw in the SQL query.

Claims (35)

1. A method for detecting an evaluation flaw in a SQL query, said SQL query configured to access data in a database table, comprising:

creating a parse tree from said SQL query;

evaluating said parse tree to ascertain whether a condition of said SQL query results in a value that is independent of contents of said database table, wherein said evaluating said parse tree further including storing a value of a select list element for subsequent expression evaluation;

performing said subsequent expression evaluation when said select list element is a part of a sub-query;

when, responsive to said evaluating, said condition is found, determining whether said condition is always true or whether said condition is always false;

when, responsive to said determining, said condition is found to be always true or always false, designating said SQL query at risk for having said evaluation flaw in said SQL query: and

rewriting the SQL query to avoid repeated performance of the condition.

2. The method of claim 1 , wherein said evaluating includes a bottom-up evaluation of said parse tree.

3. The method of claim 1 , wherein said condition is a result of a comparison operation.

4. The method of claim 1 , further comprising when said condition is found to be always true, designating said SQL query as having a tautology in said SQL query.

5. The method of claim 1 , further comprising, when said condition is found to be always false, designating said SQL query as having a contradiction in said SQL query.

6. The method of claim 1 , further comprising when said condition is found to be always true or always false, preventing said SQL query from executing.

7. A method for detecting an evaluation flaw in a SQL query, said SQL query configured to access data in a database table, comprising:

creating a parse tree from said SQL query;

evaluating step-wise, using a bottom-up methodology, through said parse tree to ascertain whether said SQL query includes a condition for said data access that when evaluated would result in a value is independent of contents of said database table, wherein said evaluating said parse tree further including storing a value of a select list element for subsequent expression evaluation;

performing said subsequent expression evaluation when said select list element is a part of a sub-query;

when, responsive to said evaluating, said condition is found, determining whether said condition is always true or whether said condition is always false;

when, responsive to said determining, said condition is found to be always true or always false, designating said SQL query at risk for having said evaluation flaw in said SQL query; and

rewriting the SQL query to avoid repeated performance of the condition.

8. The method of claim 7 , wherein said evaluating includes a bottom-up evaluation of said parse tree.

9. The method of claim 7 , wherein said evaluating includes employing a comparison operation.

10. The method of claim 7 , further comprising when said condition is found to be always true, designating said SQL query as having a tautology in said SQL query.

11. The method of claim 7 , further comprising when said condition is found to be always false, designating said SQL query as having a contradiction in said SQL query.

12. The method of claim 7 , further comprising when said condition is found to be always true or always false, preventing said SQL query from executing.

13. A method for detecting an evaluation flaw in a SQL query, said SQL query configured to access data in a database table, comprising:

creating a parse tree from said SQL query;

evaluating step-wise, using a bottom-up methodology, through said parse tree said parse tree, including:

evaluating a value of a unary expression object;

evaluating an expression involving at least said value of said unary expression object;

evaluating a condition for said data access, said condition employing said expression to ascertain whether said condition results in a value that is independent of contents of said database table, wherein said evaluating said parse tree further including storing a value of a select list element for subsequent expression evaluation;

performing said subsequent expression evaluation when said select list element is a part of a sub-query;

when, responsive to said evaluating said condition, said condition is found, determining whether said condition is always true or whether said condition is always false;

when, responsive to said determining, said condition is found to be always true or always false, designating said SQL query at risk for having said evaluation flaw in said SQL query; and

rewriting the SQL query to avoid repeated performance of the condition.

14. The method of claim 13 , wherein said evaluating said condition includes evaluating a comparison operation.

Assignments (8)
RELEASE OF FIRST LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 048077/0753 Recorded Dec 1, 2023
From: BANK OF AMERICA, N.A., AS AGENT
To: PREVOTY, INC.
Reel/Frame 065744/0045 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 048077/0795 Recorded Dec 1, 2023
From: GOLDMAN SACH BANK USA, AS AGENT
To: PREVOTY, INC.
Reel/Frame 065744/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2022
From: PREVOTY, INC.
To: IMPERVA, INC.
Reel/Frame 059786/0372 →
CHANGE OF ASSIGNEE ADDRESS Recorded Feb 23, 2022
From: PREVOTY, INC.
To: PREVOTY, INC.
Reel/Frame 059353/0953 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 15, 2019
From: PREVOTY, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 048077/0753 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 15, 2019
From: PREVOTY, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 048077/0795 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2018
From: ANAND, KUNAL
To: PREVOTY, INC.
Reel/Frame 046199/0866 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2017
From: ANAND, KUNAL; CRAMPON, MICHAEL; MEESTER, RICHARD; ROZNER, JOSEPH; CHASE, JOSHUA
To: PREVOTY, INC.
Reel/Frame 041002/0447 →
Continuity (4)
Continuation In Part 14599978 · Jan 19, 2015
Provisional Application 62220903 · Sep 18, 2015
Provisional Application 61929474 · Jan 20, 2014
Related Publication 20170068820A1 · Mar 9, 2017
Cited By (1)
US 12,483,597