IP Library Granted Patent US 10,182,068
Granted Patent B2
US 10,182,068 · App. 15/500,529 · Granted Jan 15, 2019

Determine vulnerability using runtime agent and network sniffer

Inventors: Alvaro Munoz (Las Rozas, ES); Sasi Siddharth Muthurajan (Alpharetta, GA)
Assignee: ENTIT SOFTWARE LLC
H04L63/1433G06F21/552G06F21/577H04L43/12H04L63/145H04L63/1416H04L63/1483H04L63/20G06F21/556G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,182,068
App. No.
15/500,529
Filed
Jan 31, 2017
Granted
Jan 15, 2019
Kind
B2
Art Unit
2495
USPC
726/25
Abstract

Example embodiments disclosed herein relate to determination of vulnerability of an application under test using a runtime agent and network sniffer during a security test. A runtime agent monitors execution of an application under test. A network sniffer is used to identify a probe value for determination of the vulnerability.

Claims (45)

1. A computing system comprising:

a runtime agent engine to monitor an application under test (AUT) executing at a server during a security test;

a network sniffer engine,

wherein the runtime agent engine receives a notification from the security test of an identifiable probe value,

wherein the runtime agent engine communicates the identifiable probe value to the network sniffer engine,

wherein the network sniffer engine monitors communication traffic from the AUT,

wherein the network sniffer engine identifies the identifiable probe value,

wherein the network sniffer engine provides an indication to the runtime agent engine that the identifiable probe value was identified, and

wherein the runtime agent engine provides the indication to the security test, and wherein the security test is to determine a potential AUT vulnerability based, at least in part, on the indication.

2. The computing system of claim 1 , wherein the network sniffer engine identifies the identifiable probe value in a packet, and wherein the indication includes the packet.

3. The computing system of claim 1 , wherein the computing system further includes the security test, wherein the security test receives a location of a network listener, and the security test is implemented using a scanner.

4. The computing system of claim 3 , wherein the computing system further generates an attack vector to attempt to cause the AUT to communicate with the network listener based on the potential AUT vulnerability.

5. The computing system of claim 4 , wherein the runtime agent receives another indication that the network listener has been communicated with, and provides the other indication to the security test.

6. The computing system of claim 5 , wherein the security test generates a report including the potential AUT vulnerability as a vulnerability.

7. A non-transitory machine-readable storage medium storing instructions for facilitating detection of vulnerability that, if executed by at least one processor of a computing system, cause the computing system to:

monitor, at a runtime agent, execution of an application under test executing at the device during a security test;

receive notification from the security test of an identifiable probe value;

send the identifiable probe value to a network sniffer to monitor at least one external communication of the application under test;

receive indication from the network sniffer that the network sniffer has identified the identifiable probe value; and

provide indication to the security test that the network sniffer has identified the identifiable probe value.

8. The non-transitory machine-readable storage medium of claim 7 , further comprising instructions that, if executed by the at least one processor, cause the computing system to:

receive a packet including the identifiable probe value from the network sniffer,

wherein the at least one external communication includes the packet.

9. The non-transitory machine-readable storage medium of claim 7 , further comprising instructions that, if executed by the at least one processor, cause the computing system to:

provide a location of a network listener to the security test.

10. The non-transitory machine-readable storage medium of claim 9 , wherein the application under test is further attacked by the security test to communicate with the network listener.

11. The non-transitory machine-readable storage medium of claim 10 , further comprising instructions that, if executed by the at least one processor, cause the computing system to:

receive another indication from the network listener that a communication occurred; and

provide the other indication to the security test.

12. A method comprising:

monitoring, via a runtime agent, an application under test (AUT) executing at a server during a security test;

receiving, at the runtime agent, a notification from the security test of an identifiable probe value,

communicating, by the runtime agent, the identifiable probe value to a network sniffer, wherein the network sniffer monitors communication traffic from the AUT,

identifying, at the network sniffer, the identifiable probe value during the security test,

providing, by the network sniffer, data to the runtime agent engine indicating that the identifiable probe value was identified,

wherein the runtime agent provides the data to the security test, and

wherein the security test is to determine a potential AUT vulnerability based, at least in part, on the indication.

13. The method of claim 12 , wherein the identifiable probe value is included in a packet and the data also includes the packet.

14. The method of claim 12 , wherein the security test is implemented via a scanner, the method further comprising:

generating, at the security test, an attack vector based on the data, wherein the attack vector attempts to communicate, via the potential AUT vulnerability, to a network listener; and

implementing the attack vector.

15. The method of claim 14 , further comprising:

receiving, at the network listener, communication via the implemented attack vector;

communicating the reception of the implemented attack vector back to the security test via the runtime agent; and

setting the potential AUT vulnerability as a confirmed vulnerability based on the communicated reception of the implemented attack vector.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2018
From: MUTHURAJAN, SASI SIDDHARTH
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 047677/0930 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2018
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 047721/0079 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
Continuity (1)
Related Publication 20170223043A1 · Aug 3, 2017
Cited By (18)
US 12,355,787 US 12,363,148 US 12,368,746 US 12,375,573 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,500,911 US 12,513,221 US 12,537,837 US 12,537,839 US 12,556,548 US 12,587,553 US 12,659,326 US 12,689,638 US 12,706,932