IP Library Granted Patent US 11,568,054
Granted Patent B2
US 11,568,054 · App. 16/437,962 · Granted Jan 31, 2023

Web application login macro generation and verification

Inventors: Thomas Christopher Swedlund (Alpharetta, GA); Constantine Adarchenko (Alpharetta, GA)
Assignee: MICRO FOCUS LLC
G06F21/577G06F9/45512G06F16/958
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,568,054
App. No.
16/437,962
Granted
Jan 31, 2023
Kind
B2
Abstract

A login macro to automatically log into a web application running on a server computing device is generated from a provided username, a provided password, and a provided network address of the web application. The login macro can be generated regardless of whether the web application is logged into at a starting web page at the provided network address or at a sign-in web page navigable from the starting web page. After the login macro has been generated, that usage the login macro successfully results in logging into the web application running on the server computing device can be verified.

Claims (82)

1. A method comprising:

generating, by a client computing device, a login macro to automatically log into a web application running on a server computing device, from a provided username, a provided password, and a provided network address of the web application, without user interaction;

after generating the login macro, verifying, by the client computing device, that usage of the login macro successfully results in logging into the web application running on the server computing device;

in response to successfully verifying that the usage of the login macro successfully results in logging into the web application, running the login macro to log into the web application;

after logging into the web application, probing, by the client computing device, the web application to identify security vulnerabilities within the web application; and

in response to identifying any security vulnerabilities within the web application, modifying or reconfiguring the web application to ameliorate the identified security vulnerabilities.

2. The method of claim 1 , wherein generating the login macro comprises:

navigating to a starting web page at the provided network address of the web application, without user interaction; and

locating a login form at the starting web page.

3. The method of claim 2 , wherein locating the login form at the starting web page comprises:

locating one or more form markup language elements within a document object model for the starting web page;

determining whether any located form markup language element includes a username text field sub-element, a password text field sub-element, and a submit button sub-element; and

concluding that the login form has been successfully located responsive to determining that any located form markup language element includes the username text field sub-element, the password text field sub-element, and the submit button sub-element.

4. The method of claim 3 , wherein determining whether any located form markup language element includes the username text field sub-element, the password text field sub-element, and the submit button sub-element comprises:

determining whether a given form markup language element located within the document object model includes a first text field sub-element having an associated label corresponding to a username regular expression; and

concluding that the given form markup language element includes the username text field sub-element responsive to determining that the given form markup language element includes the first text field sub-element.

5. The method of claim 4 , wherein determining whether any located form markup language element includes the username text field sub-element, the password text field sub-element, and the submit button sub-element further comprises:

after concluding that the given form markup language element includes the username text field sub-element, determining whether the given form markup language element includes a second text field sub-element having an associated label corresponding to a password regular expression and located after the first text sub-element in the given form markup language element; and

concluding that the given form markup language element includes the password text field sub-element responsive to determining that the given form markup language element includes the second text field sub-element.

6. The method of claim 5 , wherein determining whether any located form markup language element includes the username text field sub-element, the password text field sub-element, and the submit button sub-element further comprises:

after concluding that the given form markup language element includes the password text field sub-element, determining whether the given form markup language element includes a button sub-element having an associated label corresponding to a login regular expression and located after the second text sub-element in the given form markup language element; and

concluding that the given form markup language element includes the submit button sub-element responsive to determining that the given form markup language element includes the button sub-element.

7. The method of claim 3 , wherein generating the login macro further comprises, in response to successfully locating the login form at the starting web page:

creating a macro that automatically navigates to the starting web page, then automatically enters the provided username within the username text field sub-element of the login form and automatically enters the provided password within the password text field sub-element of the login, and finally automatically selects the submit button sub-element.

8. The method of claim 2 , wherein generating the login macro further comprises:

in response to unsuccessfully locating the login form at the starting web page, locating a sign-in web page navigable from the starting web page;

in response to successfully locating the sign-in web page, navigating to the sign-in web page; and

locating the login form at the sign-in web page.

9. The method of claim 8 , wherein locating the sign-in web page navigable from the starting web page comprises:

locating one or more anchor or button markup language elements within a document object model for the starting web page;

determining whether any located anchor or button markup language element corresponds to a sign-in element; and

concluding that the sign-in web page navigable from the starting web page has been successfully located responsive to determining that any located anchor or button markup language element corresponds to the sign-in element.

10. The method of claim 9 , wherein navigating to the sign-in web page comprises:

selecting a located anchor or button markup language element within the document object model that corresponds to the sign-in element.

11. The method of claim 9 , wherein determining whether any located anchor or button markup language element corresponds to the sign-in element comprises:

determining whether a given anchor or button markup language element located within the document object model has an associated label corresponding to a login regular expression; and

concluding that the given anchor or button markup language element corresponds to the sign-in element responsive to determining that the given anchor or button markup language element has the associated label.

12. The method of claim 8 , wherein locating the login form at the sign-in web page comprises:

locating one or more form markup language elements within a document object model for the sign-in web page;

determining whether any located form markup language element includes a username text field sub-element, a password text field sub-element, and a submit button sub-element; and

concluding that the login form has been successfully located responsive to determining that any located form markup language element includes the username text field sub-element, the password text field sub-element, and the submit button sub-element.

13. The method of claim 12 , wherein generating the login macro further comprises, in response to successfully locating the login form at the sign-in web page:

creating a macro that automatically navigates to the sign-in web page, then automatically enters the provided username within the username text field sub-element of the login form and automatically enters the provided password within the password text field sub-element of the login, and finally automatically selects the submit button sub-element.

14. The method of claim 1 , wherein verifying that the usage of the login macro successfully results in logging into the web application comprises:

running the login macro;

locating a sign-out element within a document object model for a web page at which running of the login macro ends; and

in response to successfully locating the sign-out element, concluding that the usage of the login macro successfully results in logging into the web application.

15. The method of claim 14 , wherein locating the sign-out element within the document object model comprises:

locating one or more anchor or button markup language elements within the document object model;

determining whether any located anchor or button markup language element corresponds to the sign-out element; and

concluding that the sign-out element has been successfully located responsive to determining that any located anchor or button markup language element corresponds to the sign-out element.

16. The method of claim 15 , wherein determining whether any located anchor or button markup language element corresponds to the sign-out element comprises:

determining whether a given anchor or button markup language element located within the document object model has an associated label corresponding to a logout regular expression; and

concluding that the given anchor or button markup language element corresponds to the sign-out element responsive to determining that the given anchor or button markup language element has the associated label.

17. A non-transitory computer-readable data storage medium storing program code executable by a processor to perform processing comprising:

generating a login macro to automatically log into a web application running on a server computing device, from a provided username, a provided password, and a provided network address of the web application, without user interaction;

after generating the login macro, verifying that usage of the login macro successfully results in logging into the web application running on the server computing device;

in response to successfully verifying that the usage of the login macro successfully results in logging into the web application, running the login macro to log into the web application;

after logging into the web application, probing the web application to identify security vulnerabilities within the web application; and

in response to identifying any security vulnerabilities within the web application, modifying or reconfiguring the web application to ameliorate the identified security vulnerabilities.

18. The non-transitory computer-readable data storage medium of claim 17 , wherein generating the login macro comprises:

navigating to a starting web page at the provided network address of the web application, without user interaction;

locating a login form at the starting web page;

in response to unsuccessfully locating the login form at the starting web page, locating a sign-in web page navigable from the starting web page;

in response to successfully locating the sign-in web page, navigating to the sign-in web page; and

locating the login form at the sign-in web page; and

in response to successfully locating the login form at the sign-in web page, creating the login macro that automatically navigates to the sign-in web page, then automatically enters the provided username within the username text field sub-element of the login form and automatically enters the provided password within a password text field sub-element of the login, and finally automatically selects a submit button sub-element.

19. The non-transitory computer-readable data storage medium of claim 18 , wherein locating the sign-in web page navigable from the starting web page comprises:

locating one or more anchor or button markup language elements within a document object model for the starting web page;

determining whether any located anchor or button markup language element corresponds to a sign-in element by determining whether a given anchor or button markup language element located within the document object model has an associated label corresponding to a login regular expression; and; and

concluding that the sign-in web page navigable from the starting web page has been successfully located responsive to determining that any located anchor or button markup language element corresponds to the sign-in element,

wherein navigating to the sign-in web page comprises:

selecting a located anchor or button markup language element within the document object model that corresponds to the sign-in element.

20. A computing device comprising:

network hardware to communicatively connect the computing device to a server computing device running a web application;

a non-transitory computer-readable data storage medium storing program code; and

a processor to execute the program code to:

generate a login macro to automatically log into the web application, from a provided username, a provided password, and a provided network address of the web application, without user interaction, regardless of whether the web application is logged into at a starting web page at the provided network address or at a sign-in web page navigable from the starting web page;

after generating the login macro, verify that usage of the login macro successfully results in logging into the web application running on the server computing device;

in response to successfully verifying that the usage of the login macro successfully results in logging into the web application, run the login macro to log into the web application;

after logging into the web application, probe the web application to identify security vulnerabilities within the web application; and

in response to identifying any security vulnerabilities within the web application, modifying or reconfiguring the web application to ameliorate the identified security vulnerabilities.

Assignments (6)
RELEASE OF SECURITY INTEREST REEL/FRAME 052294/0522 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062624/0449 →
RELEASE OF SECURITY INTEREST REEL/FRAME 052295/0041 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062625/0754 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: MICRO FOCUS LLC; BORLAND SOFTWARE CORPORATION; MICRO FOCUS SOFTWARE INC.; NETIQ CORPORATION; MICRO FOCUS (US), INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052294/0522 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: MICRO FOCUS LLC; BORLAND SOFTWARE CORPORATION; MICRO FOCUS SOFTWARE INC.; NETIQ CORPORATION; MICRO FOCUS (US), INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052295/0041 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2019
From: SWEDLUND, THOMAS CHRISTOPHER; ADARCHENKO, CONSTANTINE
To: ENTIT SOFTWARE LLC
Reel/Frame 049436/0493 →