IP Library Granted Patent US 10,243,679
Granted Patent B2
US 10,243,679 · App. 15/605,345 · Granted Mar 26, 2019

Vulnerability detection

Inventors: Shawn Morgan Simpson (Alpharetta, GA); Philip Edward Hamer (Alpharetta, GA)
Assignee: ENTIT SOFTWARE LLC
H04B17/17H04B17/102H04B17/318H04W24/04H04W88/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,243,679
App. No.
15/605,345
Granted
Mar 26, 2019
Kind
B2
Abstract

In some examples, a system receives a response from a web server, the response being responsive to a web request sent to the web server. The system executes a script in the response with a web browser, links a document object model (DOM) method to application code executed during the executing of the script, and determines a vulnerability based on the DOM method linked during the executing of the script.

Claims (46)

1. A non-transitory machine-readable storage medium storing instructions that upon execution cause a system to:

receive a response from a web server, the response being responsive to a web request sent to the web server;

execute a script in the response with a web browser;

link a document object model (DOM) method to application code executed during the executing of the script; and

determine a vulnerability based on the DOM method linked during the executing of the script.

2. The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:

intercept a web request from the web browser; and

modify the intercepted web request to form the web request sent to the web server.

3. The non-transitory machine-readable storage medium of claim 2 , wherein modifying the intercepted web request to form the web request sent to the web server comprises injecting a cross site scripting payload into the intercepted web request.

4. The non-transitory machine-readable storage medium of claim 3 , wherein the determined vulnerability comprises a cross-site vulnerability in which an attacker is able to inject a script into a web page viewed by a user.

5. The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:

link a plurality of DOM methods called by the web browser to the application code during the executing of the script,

wherein determining the vulnerability is based on the linked plurality of DOM methods.

6. The non-transitory machine-readable storage medium of claim 5 , wherein determining the vulnerability is based on detecting a particular sequence of the linked plurality of DOM methods called by the web browser.

7. The non-transitory machine-readable storage medium of claim 1 , wherein the DOM method is an element of a DOM that defines a logical structure of a markup language document of a web page.

8. A system comprising:

a processor; and

a non-transitory storage medium storing instructions executable on the processor to:

receive a response from a web server, the response being responsive to a web request sent to the web server;

execute a script in the response with a web browser;

link a document object model (DOM) method called by the web browser to application code executed during the executing of the script; and

determine a vulnerability of a web site based on the DOM method linked during the executing of the script.

9. The system of claim 8 , wherein the instructions are executable on the processor to:

intercept a web request from the web browser; and

modify the intercepted web request to form the web request sent to the web server.

10. The system of claim 8 , wherein modifying the intercepted web request to form the web request sent to the web server comprises injecting malicious code into the intercepted web request.

11. The system of claim 8 , wherein the determined vulnerability is based on detecting that the DOM method linked during the executing of the script is a particular DOM method expected to be called when the vulnerability is present.

12. The system of claim 11 , wherein the DOM method is an element of a DOM that defines a logical structure of a markup language document of the web page.

13. The system of claim 8 , wherein the instructions are executable on the processor to:

link a plurality of DOM methods to the application code during the executing of the script,

wherein the vulnerability is based on the linked plurality of DOM methods.

14. The system of claim 13 , wherein the vulnerability is based on detecting a particular sequence of the linked plurality of DOM methods.

15. A method comprising:

receiving, by a system comprising a processor, a response from a web server, the response being responsive to a web request sent to the web server;

executing, by the system, a script in the response with a web browser;

linking, by the system, a document object model (DOM) method called by the web browser to application code executed during the executing of the script; and

determining, by the system, a vulnerability of a web site based on detecting that the DOM method linked during the executing of the script is a particular DOM method expected to be called when the vulnerability is present.

16. The method of claim 15 , further comprising:

intercepting, by the system, a web request from the web browser; and

modifying, by the system, the intercepted web request to form the web request sent to the web server.

17. The method of claim 15 , wherein the determined vulnerability comprises a cross-site vulnerability in which an attacker is able to inject a script into a web page viewed by a user.

18. The method of claim 17 , wherein the DOM method is an element of a DOM that defines a logical structure of a markup language document of the web page.

19. The method of claim 15 , further comprising:

linking, by the system, a plurality of DOM methods to the application code during the executing of the script,

wherein the vulnerability is based on the linked plurality of DOM methods.

20. The method of claim 19 , wherein the vulnerability is based on detecting a particular sequence of the linked plurality of DOM methods.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 052294/0522 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062624/0449 →
RELEASE OF SECURITY INTEREST REEL/FRAME 052295/0041 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062625/0754 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: MICRO FOCUS LLC; BORLAND SOFTWARE CORPORATION; MICRO FOCUS SOFTWARE INC.; NETIQ CORPORATION; MICRO FOCUS (US), INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052294/0522 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: MICRO FOCUS LLC; BORLAND SOFTWARE CORPORATION; MICRO FOCUS SOFTWARE INC.; NETIQ CORPORATION; MICRO FOCUS (US), INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052295/0041 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2018
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 048261/0084 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2017
From: SIMPSON, SHAWN MORGAN; HAMER, PHILIP EDWARD
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 042510/0222 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2017
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 042583/0001 →
Continuity (3)
Continuation 15003262 · Jan 21, 2016
Continuation 14115648
Related Publication 20170264378A1 · Sep 14, 2017