IP Library Granted Patent US 10,423,793
Granted Patent B2
US 10,423,793 · App. 15/317,206 · Granted Sep 24, 2019

Install runtime agent for security test

Inventors: Matias Madou (Diegem, BE); Ronald J. Sechman (Alpharetta, GA); Sam Ng Ming Sum (Hong Kong, CN)
Assignee: ENTIT SOFTWARE LLC
G06F21/577G06F11/3612G06F11/3672G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,423,793
App. No.
15/317,206
Granted
Sep 24, 2019
Kind
B2
Abstract

Example embodiments disclosed herein relate to an approach for installing a runtime agent during a security test. A security test is initiated or performed on an application under test executing on a server. An application vulnerability associated with the application under test is determined. The application vulnerability is exploited to install the runtime agent on the server. The security test is continued using the runtime agent to receive additional information about the application under test.

Claims (42)

1. A non-transitory machine-readable storage medium storing instructions that, if executed by at least one processor of a device, cause the device to:

initiate a security test on an application under test (AUT) to execute at a server;

determine an application vulnerability associated with the AUT;

determine a first framework used at the server and associated with the AUT;

select a first runtime agent from a group of runtime agents based on determining that the first framework associated with the AUT is used at the server, wherein different runtime agents of the group of runtime agents are associated with respective different frameworks, wherein the selecting of the first runtime agent is based on accessing a data structure that correlates the different runtime agents with the respective different frameworks;

exploit the application vulnerability to install the first runtime agent on the server, the exploiting comprising providing a script to the AUT via the application vulnerability to cause download of the first runtime agent, and unpacking the first runtime agent for the installation at the server;

restart the AUT prior to a continuation of the security test and after the installation of the first runtime agent; and

continue the security test using the first runtime agent to receive additional information about the AUT.

2. The non-transitory machine-readable storage medium of claim 1 , wherein the first runtime agent is used to provide the additional information about internal operations performed by the AUT.

3. The non-transitory machine-readable storage medium of claim 1 , wherein the determined application vulnerability comprises a vulnerability of the AUT to injection of code onto the server via the AUT.

4. The non-transitory machine-readable storage medium of claim 1 , further comprising instructions that if executed cause the device to:

add a header to an application request sent to the AUT, the header comprising information useable by the first runtime agent to diagnose the application vulnerability.

5. The non-transitory machine-readable storage medium of claim 4 , wherein the header further comprise a payload used by the device in an attack of the AUT as part of the security test.

6. The non-transitory machine-readable storage medium of claim 4 , further comprising instructions that if executed cause the device to:

receive information from the first runtime agent responsive to the header, the received information comprising information of portions of code executed by the AUT in response to the application request.

7. The non-transitory machine-readable storage medium of claim 4 , further comprising instructions that if executed cause the device to:

receive information from the first runtime agent responsive to the header, the received information comprising information of an internal operation of the AUT responsive to the application request.

8. A method performed by a system comprising a hardware processor, comprising:

initiating a security test on an application under test (AUT) executing at a server;

determining an application vulnerability associated with the AUT during the security test;

determining a first framework associated with the AUT and used at the server;

selecting a first runtime agent from a group of runtime agents based on determining that the first framework associated with the AUT is used at the server, wherein different runtime agents of the group of runtime agents are associated with respective different frameworks, wherein the selecting of the first runtime agent is based on accessing a data structure that correlates the different runtime agents with the respective different frameworks;

exploiting the application vulnerability to provide a script on the server, wherein the script causes the server to download the first runtime agent, unpack the first runtime agent, and install the first runtime agent;

restarting the AUT prior to a continuation of the security test and after the installation of the first runtime agent; and

continuing the security test using the first runtime agent executing at the server to receive additional information about the AUT.

9. The method of claim 8 , wherein the first runtime agent is used to provide the additional information about what is being executed by the AUT.

10. The method of claim 8 , wherein the determined application vulnerability includes command injection.

11. A computing system comprising:

a processor; and

a non-transitory storage medium storing instructions executable on the processor to:

perform a security test on an application under test (AUT) to execute on a server; determine that an application vulnerability associated with the AUT identified by the security test is capable of an injection exploit;

determine a first framework used at the server and associated with the AUT;

select a first runtime agent from a group of runtime agents based on determining that the first framework associated with the AUT is used at the server, wherein different runtime agents of the group of runtime agents are associated with respective different frameworks, wherein the selecting of the first runtime agent is based on accessing a data structure that correlates the different runtime agents with the respective different frameworks;

exploit the application vulnerability to download a script to the server to cause the server to download the first runtime agent, unpack the first runtime agent, and install the first runtime agent;

restart the AUT prior to a continuation of the security test and after the installation of the first runtime agent; and

continue the security test using the first runtime agent executing at the server to receive additional information about the AUT including requested trace information about what is executing at the AUT.

12. The computing system of claim 11 , wherein the instructions are executable on the processor to:

use the additional information to perform an attack vector on the AUT.

13. The computing system of claim 11 , wherein the instructions are executable on the processor to:

add a header to an application request sent to the AUT, the header comprising information useable by the first runtime agent to diagnose the application vulnerability.

14. The computing system of claim 13 , wherein the instructions are executable on the processor to:

receive information from the first runtime agent responsive to the header, the received information comprising information of portions of code executed by the AUT in response to the application request.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2016
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 040942/0128 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2016
From: MADOU, MATIAS; SECHMAN, RONALD JOSEPH; NG MING SUM, SAM
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 040599/0297 →
Continuity (1)
Related Publication 20170103211A1 · Apr 13, 2017
Cited By (19)
US 12,355,787 US 12,363,148 US 12,368,746 US 12,375,573 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,500,911 US 12,513,221 US 12,537,837 US 12,537,839 US 12,556,548 US 12,587,553 US 12,651,072 US 12,659,326 US 12,689,638 US 12,706,932