IP Library Granted Patent US 11,601,462
Granted Patent B2
US 11,601,462 · App. 17/105,239 · Granted Mar 7, 2023

Systems and methods of intelligent and directed dynamic application security testing

Inventors: Joseph Feiman (Stamford, CT); Eric Sheridan (Greensboro, NC); Prabhuram Mohan (San Jose, CA)
Assignee: Synopsys, Inc.
H04L63/1433G06F8/00G06F9/44589G06F9/547G06F11/3664G06N3/02H04L63/1425H04L63/1441H04L63/1475
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,601,462
App. No.
17/105,239
Granted
Mar 7, 2023
Kind
B2
Abstract

Disclosed are systems, methods and computer readable mediums for intelligent and directed dynamic application security testing. The systems, methods and computer-readable mediums can be configured to receive an attack location and an attack type for a web-application, transmit the attack location and attack type to a ID-DAST platform, receive from the ID-DAST platform a payload, attack the web-application using the payload, and receive results of the attack.

Claims (39)

1. A system for intelligent directed dynamic application security testing, the system comprising:

a processor; and

a computer-readable medium storing instructions, which when executed by the processor causes the processor to:

receive an attack scenario for at least one of a web-application or a microservice;

transmit to a platform the attack scenario;

receive from the platform a payload;

attack the web-application or the microservice using the payload; and

receive results of the attack, wherein the attack scenario comprises at least an attack location and an attack type, wherein detection and identification of the attack location and the attack type are provided by a non-crawling source.

2. The system of claim 1 , wherein the non-crawling source is at least one of: Application Programming Interface (API) detected via monitoring application traffic, Graphical User Interface (GUI) action detected via monitoring application traffic, static application security testing, analysis of code/build units of the web application or the microservice, analysis of application development, quality assurance, or testing, security analytics and statistics, or historical attack scenarios.

3. The system of claim 1 , wherein the detection, identification and testing do not require a pre-application-runtime declaration of Application Programming Interfaces (API).

4. The system of claim 1 , wherein Application Programming Interfaces (API) are determined at runtime.

5. The system of claim 1 , wherein the web application or the microservice is one of an individual unit-build, a single code unit, a module, one or more Application Programming Interfaces, or a master build.

6. The system of claim 1 , where the web application or the microservice is accessed and tested by using login credentials or session-state identifiers.

7. The system of claim 6 , wherein the login credentials or session-state identifiers are automatically detected.

8. The system of claim 1 , wherein the payload is determined and dynamically constructed, at runtime, based on the platform applying analytics to the attack scenario.

9. The system of claim 1 , comprising further instructions, which when executed by the processor causes the processor to:

transmit the results of the attack to a neural network; and

receive verification the attack was successful.

10. The system of claim 9 , wherein the neural network uses historical request and response pairs for the verification.

11. A non-transitory computer-readable medium storing instructions, which when executed by at least one processor causes the at least one processor to:

receive an attack scenario for at least one of a web-application or a microservice;

transmit to a platform the attack scenario;

receive from the platform a payload;

attack the web-application or microservice using the payload; and

receive results of the attack, wherein the attack scenario comprises at least an attack location and an attack type, wherein detection and identification of the attack location and the attack type are provided by a non-crawling source.

12. The non-transitory computer-readable medium of claim 11 , wherein the detection, identification and testing do not require a pre-application-runtime declaration of Application Programming Interfaces (API).

13. The non-transitory computer-readable medium of claim 11 , wherein the payload is determined and dynamically constructed, at runtime, based on the platform applying analytics to the attack scenario.

14. The non-transitory computer-readable medium of claim 11 , wherein at least one of the web application or the microservice is one of an individual unit-build, a single code unit, a module, one or more Application Programming Interfaces, or a master build.

15. The non-transitory computer-readable medium of claim 11 , wherein the non-crawling source is at least one of: Application Programming Interface (API) detected via monitoring application traffic, Graphical User Interface (GUI) action detected via monitoring application traffic, static application security testing, analysis of code/build units of the web application or the microservice, analysis of application development, quality assurance, or testing, security analytics and statistics, or historical attack scenarios.

16. A method comprising:

receiving an attack scenario for at least one of a web-application or a microservice;

transmitting to a platform the attack scenario;

receiving from the platform a payload;

attacking the web-application or microservice using the payload; and

receiving results of the attack, wherein the attack scenario comprises at least an attack location and an attack type, wherein detection and identification of the attack location and the attack type are provided by a non-crawling source.

17. The method of claim 16 , wherein at least one of the web application or the microservice is one of an individual unit-build, a single code unit, a module, one or more Application Programming Interfaces, or a master build.

18. The method of claim 16 , where at least one of the web application or the microservice is accessed and tested by using at least one of login credentials or session-state identifiers.

19. The method of claim 18 , wherein at least one of the login credentials or session-state identifiers are automatically detected.

20. The method of claim 16 , wherein the payload is determined and dynamically constructed, at runtime, based on the platform applying analytics to the attack scenario.

Assignments (7)
SECURITY INTEREST Recorded Sep 30, 2024
From: BLACK DUCK SOFTWARE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 069083/0149 →
CHANGE OF NAME Recorded Jul 30, 2024
From: SOFTWARE INTEGRITY GROUP, INC.
To: BLACK DUCK SOFTWARE, INC.
Reel/Frame 068191/0490 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2024
From: SYNOPSYS, INC.
To: SOFTWARE INTEGRITY GROUP, INC.
Reel/Frame 066664/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2022
From: SYNOPSYS SOFTWARE INTEGRITY SOLUTIONS, INC.
To: SYNOPSYS, INC.
Reel/Frame 060698/0193 →
CHANGE OF NAME Recorded Jul 25, 2022
From: NTT SECURITY APPSEC SOLUTIONS INC.
To: SYNOPSYS SOFTWARE INTEGRITY SOLUTIONS, INC.
Reel/Frame 060884/0443 →
CHANGE OF NAME Recorded Oct 13, 2021
From: WHITEHAT SECURITY, INC.
To: NTT SECURITY APPSEC SOLUTIONS INC.
Reel/Frame 057793/0037 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FEIMAN, JOSEPH; SHERIDAN, ERIC; MOHAN, PRABHURAM
To: WHITEHAT SECURITY, INC.
Reel/Frame 056292/0039 →