IP Library Granted Patent US 10,855,717
Granted Patent B1
US 10,855,717 · App. 16/891,996 · Granted Dec 1, 2020

Systems and methods of intelligent and directed dynamic application security testing

Inventors: Joseph Feiman (Stamford, CT); Eric Sheridan (Greensboro, NC); Prabhuram Mohan (San Jose, CA)
Assignee: WHITEHAT SECURITY, INC.
H04L63/1433G06F8/00G06F9/44589G06F9/547G06F11/3664G06N3/02H04L63/1425H04L63/1441H04L63/1475
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,855,717
App. No.
16/891,996
Granted
Dec 1, 2020
Kind
B1
Abstract

Disclosed are systems, methods and computer readable mediums for intelligent and directed dynamic application security testing. The systems, methods and computer-readable mediums can be configured to receive an attack location and an attack type for a web-application, transmit the attack location and attack type to a ID-DAST platform, receive from the ID-DAST platform a payload, attack the web-application using the payload, and receive results of the attack.

Claims (36)

1. A system for intelligent directed dynamic application security testing, the system comprising:

a processor; and

a computer-readable medium storing instructions, which when executed by the processor causes the processor to:

receive an attack location and an attack type for a web-application or a microservice;

transmit, to a platform, the attack location and the attack type;

receive, from the platform, a payload;

attack the web-application or the microservice using the payload; and

receive results of the attack.

2. The system of claim 1 , wherein the attack location and the attack type are provided by at least by one of: Application Programming Interfaces (APIs) detected via monitoring application traffic, a status of source/byte/binary code of the web application or the microservice, static application security testing, Open Web Application Security Project Top 10, and security analytics/statistics.

3. The system of claim 2 , wherein an Application Programming Interface detection and testing do not require a preliminary, pre-application-runtime declaration of APIs.

4. The system of claim 1 , wherein the platform includes historical attack scenarios for web-applications.

5. The system of claim 4 , wherein the payload includes at least a sequence of steps to carry out a selected attack scenario of the historical attack scenarios.

6. The system of claim 1 , comprising further instructions, which when executed by the processor causes the processor to: transmit the results of the attack to a neural network; and receive verification the attack was successful.

7. The system of claim 1 , wherein the neural network uses historical request and response pairs for the verification.

8. A non-transitory computer-readable medium storing instructions, which when executed by at least one processor causes the at least one processor to:

receive an attack location and an attack type for a web-application or a microservice;

transmit, to a platform, the attack location and the attack type;

receive, from the platform, a payload;

attack the web-application or the microservice using the payload; and

receive results of the attack.

9. The non-transitory computer-readable medium of claim 8 , wherein the attack location and the attack type are provided by at least by one of: Application Programming Interfaces (APIs) detected via monitoring application traffic, a status of source/byte/binary code of the web application or the microservice, static application security testing, Open Web Application Security Project Top 10, and security analytics/statistics.

10. The non-transitory computer-readable medium of claim 9 , wherein an Application Programming Interface detection and testing do not require a preliminary, pre-application-runtime declaration of APIs.

11. The non-transitory computer-readable medium of claim 8 , wherein the platform includes historical attack scenarios for web-applications.

12. The non-transitory computer-readable medium of claim 11 , wherein the payload includes at least a sequence of steps to carry out a selected attack scenario of the historical attack scenarios.

13. The non-transitory computer-readable medium of claim 8 , comprising further instructions, which when executed by the processor causes the processor to: transmit the results of the attack to a neural network; and receive verification the attack was successful.

14. The non-transitory computer-readable medium of claim 8 , wherein the neural network uses historical request and response pairs for the verification.

15. A method comprising:

receiving an attack location and an attack type for a web-application or a microservice;

transmitting, to a platform, the attack location and the attack type;

receiving, from the platform, a payload;

attacking the web-application or the microservice using the payload; and

receiving results of the attack.

16. The method of claim 15 , wherein the attack location and the attack type are provided by at least by one of: Application Programming Interfaces (APIs) detected via monitoring application traffic, a status of source/byte/binary code of the web application or the microservice, static application security testing, Open Web Application Security Project Top 10, and security analytics/statistics.

17. The method of claim 16 , wherein an Application Programming Interface detection and testing do not require a preliminary, pre-application-runtime declaration of APIs.

18. The method of claim 15 , wherein the platform includes historical attack scenarios for web-applications.

19. The method of claim 15 , wherein the payload includes at least a sequence of steps to carry out a selected attack scenario of the historical attack scenarios.

Assignments (7)
SECURITY INTEREST Recorded Sep 30, 2024
From: BLACK DUCK SOFTWARE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 069083/0149 →
CHANGE OF NAME Recorded Jul 30, 2024
From: SOFTWARE INTEGRITY GROUP, INC.
To: BLACK DUCK SOFTWARE, INC.
Reel/Frame 068191/0490 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2024
From: SYNOPSYS, INC.
To: SOFTWARE INTEGRITY GROUP, INC.
Reel/Frame 066664/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2022
From: SYNOPSYS SOFTWARE INTEGRITY SOLUTIONS, INC.
To: SYNOPSYS, INC.
Reel/Frame 060698/0193 →
CHANGE OF NAME Recorded Jul 25, 2022
From: NTT SECURITY APPSEC SOLUTIONS INC.
To: SYNOPSYS SOFTWARE INTEGRITY SOLUTIONS, INC.
Reel/Frame 060884/0443 →
CHANGE OF NAME Recorded Jul 22, 2022
From: WHITEHAT SECURITY, INC.
To: NTT SECURITY APPSEC SOLUTIONS INC.
Reel/Frame 060829/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FEIMAN, JOSEPH; SHERIDAN, ERIC; MOHAN, PRABHURAM
To: WHITEHAT SECURITY, INC.
Reel/Frame 056292/0026 →