IP Library Granted Patent US 10,936,727
Granted Patent B2
US 10,936,727 · App. 16/676,880 · Granted Mar 2, 2021

Detection of second order vulnerabilities in web services

Inventors: Yair Amit (Tel-Aviv, IL); Evgeny Beskrovny (Ramat Gan, IL); Omer Tripp (San Jose, CA)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/577H04L63/1433G05B2219/31085G05B2219/32136G06F9/30058G07B2017/00911H04L67/02H04W12/00514
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,936,727
App. No.
16/676,880
Granted
Mar 2, 2021
Kind
B2
Abstract

A method detecting a vulnerability in a Web service can include determining, using a processor, whether a Web service uses identity of a requester to select one of a plurality of different paths of a branch in program code of the Web service. The method further can include, responsive to determining that the Web service does select one of a plurality of different paths of a branch according to identity of the requester, indicating that the Web service has a potential vulnerability.

Claims (48)

1. A computer-implemented method performed by a security system configured to test a Web service, comprising:

performing, by the security system, a static analysis on the Web service;

locating, during the static analysis, a seed instruction in program code of the Web service in which identity of a requester is determined by the Web service;

determining, during the static analysis, whether a value from the seed instruction is determinative in selecting between a plurality of paths for a branch in the program code; and

indicating, by the security system and responsive to the determining, that the Web service has a potential vulnerability based upon the Web service selecting one of the plurality of paths according to the identity of the requester.

2. The method of claim 1 , wherein

a trusted identity to which identity is compared is determined, and

a payload is submitted to the Web service in which the trusted identify is impersonated.

3. The method of claim 2 , wherein

the program code of the Web service is instrumented with first diagnostic program code configured to determine the trusted identity responsive to execution of the Web service.

4. The method of claim 2 , wherein

a response to the payload from the Web service is compared with an expected response; and

the indicating is based upon the comparing.

5. The method of claim 1 , wherein

the program code of the Web service is instrumented using second diagnostic program code configured to defeat identity decryption within the Web service responsive to execution of the Web service.

6. A computer hardware system including a security system configured to test a Web service, comprising:

a hardware processor configured to initiate the following executable operations:

performing, by the security system, a static analysis on the Web service;

locating, during the static analysis, a seed instruction in program code of the Web service in which identity of a requester is determined by the Web service;

determining, during the static analysis, whether a value from the seed instruction is determinative in selecting between a plurality of paths for a branch in the program code; and

indicating, by the security system and responsive to the determining, that the Web service has a potential vulnerability based upon the Web service selecting one of the plurality of paths according to the identity of the requester.

7. The system of claim 6 , wherein

a trusted identity to which identity is compared is determined, and

a payload is submitted to the Web service in which the trusted identify is impersonated.

8. The system of claim 7 , wherein

the program code of the Web service is instrumented with first diagnostic program code configured to determine the trusted identity responsive to execution of the Web service.

9. The system of claim 7 , wherein

a response to the payload from the Web service is compared with an expected response; and

the indicating is based upon the comparing.

10. The system of claim 6 , wherein

the program code of the Web service is instrumented using second diagnostic program code configured to defeat identity decryption within the Web service responsive to execution of the Web service.

11. A computer program product, comprising:

a hardware storage device having stored therein computer executable program code,

the computer executable program code, which when executed by a computer hardware system including a security system configured to test a Web service, causes the computer hardware system to perform:

performing, by the security system, a static analysis on the Web service;

locating, during the static analysis, a seed instruction in program code of the Web service in which identity of a requester is determined by the Web service;

determining, during the static analysis, whether a value from the seed instruction is determinative in selecting between a plurality of paths for a branch in the program code; and

indicating, by the security system and responsive to the determining, that the Web service has a potential vulnerability based upon the Web service selecting one of the plurality of paths according to the identity of the requester.

12. The computer program product of claim 11 , wherein

a trusted identity to which identity is compared is determined, and

a payload is submitted to the Web service in which the trusted identify is impersonated.

13. The computer program product of claim 12 , wherein

the program code of the Web service is instrumented with first diagnostic program code configured to determine the trusted identity responsive to execution of the Web service.

14. The computer program product of claim 12 , wherein

a response to the payload from the Web service is compared with an expected response; and

the indicating is based upon the comparing.

15. The computer program product of claim 11 , wherein

the program code of the Web service is instrumented using second diagnostic program code configured to defeat identity decryption within the Web service responsive to execution of the Web service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2019
From: AMIT, YAIR; BESKROVNY, EVGENY; TRIPP, OMER
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 050947/0745 →
Continuity (3)
Continuation 13430002 · Mar 26, 2012
Continuation 13335439 · Dec 22, 2011
Related Publication 20200074087A1 · Mar 5, 2020