IP Library Granted Patent US 8,347,392
Granted Patent B2
US 8,347,392 · App. 11/510,135 · Granted Jan 1, 2013

Apparatus and method for analyzing and supplementing a program to provide security

Assignee: Hewlett-Packard Development Company, L.P.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,347,392
App. No.
11/510,135
Granted
Jan 1, 2013
Kind
B2
Abstract

A computer readable storage medium has executable instructions to perform an automated analysis of program instructions. The automated analysis includes at least two analyses selected from an automated analysis of injection vulnerabilities, an automated analysis of potential repetitive attacks, an automated analysis of sensitive information, and an automated analysis of specific HTTP attributes. Protective instructions are inserted into the program instructions. The protective instructions are utilized to detect and respond to attacks during execution of the program instructions.

Claims (27)

1. A non-transitory computer readable storage medium, comprising executable instructions to:

perform an automated analysis of program instructions using a security module to analyze application output prior to the program instructions being invoked, wherein the automated analysis includes an automated analysis of injection vulnerabilities, an automated analysis of potential repetitive attacks including session ID guessing, credential guessing, click fraud and site probing, an automated analysis of sensitive information, and an automated analysis of specific HTTP attributes;

select and insert protective instructions into the program instructions based on the automated analysis of the injection vulnerabilities, wherein the protective instructions comprise a call that generates a security event during runtime; and

utilize a runtime security module to detect and respond to attacks by analyzing the generated security event during execution of the program instructions.

2. The computer readable storage medium of claim 1 wherein the automated analysis of injection vulnerabilities includes a separate automated analysis of SQL injection, command injection, resource injection, log forging and cross site scripting.

3. The computer readable storage medium of claim 1 wherein sensitive information includes error mining, sensitive data extraction, and a privacy violation.

4. The computer readable storage medium of claim 1 wherein specific HTTP attributes include session fixation, anonymous access, publicly available attack tools, and forceful browsing.

5. The compute readable storage medium of claim 1 , wherein the executable instructions include executable instructions to log information.

6. The compute readable storage medium of claim 1 , wherein the executable instructions include executable instructions to generate an alert.

7. The compute readable storage medium of claim 1 , wherein the executable instructions include executable instructions to halt the processing of a request.

8. The compute readable storage medium of claim 1 , wherein the executable instructions include executable instructions to defuse an attack.

9. The compute readable storage medium of claim 1 , wherein the executable instructions include executable instructions to issue a challenge.

10. The compute readable storage medium of claim 1 , wherein the executable instructions include executable instructions to slow down an application.

11. The compute readable storage medium of claim 1 , wherein the executable instructions include executable instructions to shut down an application.

12. The compute readable storage medium of claim 1 , wherein the executable instructions include executable instructions to invoke a user-defined response.

13. A non-transitory computer readable storage medium, comprising executable instructions to:

perform an automated analysis of program instructions using a security module to analyze application output prior to the program instructions being invoked, wherein the automated analysis includes a separate automated analysis of potential repetitive attacks including;

session ID guessing,

credential guessing,

click fraud, and

site probing;

select and insert protective instructions into the program instructions in response to and based on the automated analysis, wherein the protective instructions comprise a call that generates a security event during runtime; and

utilize a runtime security module to invoke a runtime security module that operates to detect and respond to attacks by analyzing the generated security event during execution of the program instructions.

14. The computer readable storage medium of claim 13 wherein the automated analysis includes an automated analysis of injection vulnerabilities, an automated analysis of sensitive information, and an automated analysis of specific HTTP attributes.

15. The computer readable storage medium of claim 14 wherein the automated analysis of injection vulnerabilities includes a separate automated analysis of SQL injection, command injection, resource injection, log forging and cross site scripting.

16. The computer readable storage medium of claim 14 wherein sensitive information includes error mining, sensitive data extraction, and a privacy violation.

17. The computer readable storage medium of claim 14 wherein specific HTTP attributes include session fixation, anonymous access, publicly available attack tools, and forceful browsing.

Assignments (11)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
MERGER Recorded Nov 16, 2012
From: FORTIFY SOFTWARE, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029316/0274 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: HEWLETT-PACKARD SOFTWARE, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029316/0280 →
CERTIFICATE OF CONVERSION Recorded Apr 20, 2011
From: FORTIFY SOFTWARE, INC.
To: FORTIFY SOFTWARE, LLC
Reel/Frame 026155/0089 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2006
From: CHESS, BRIAN; DO, ARTHUR; THORNTON, ROGER
To: FORTIFY SORWARE, INC.
Reel/Frame 018443/0212 →
Continuity (2)
Provisional Application 60711972 · Aug 25, 2006
Related Publication 20070074169A1 · Mar 29, 2007