IP Library › Granted Patent US 9,053,319
Granted Patent B2
US 9,053,319 · App. 13/248,981 · Granted Jun 9, 2015

Context-sensitive taint processing for application security

Inventors: Brian V Chess (Palo Alto, CA); Sean Patrick Fay (San Francisco, CA)
Assignee: Hewlett-Packard Development Company, L.P.
G06F21/53H04L63/1433G06F21/54G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,053,319
App. No.
13/248,981
Filed
Sep 29, 2011
Granted
Jun 9, 2015
Kind
B2
Art Unit
2497
USPC
726/25
Abstract

In one implementation, a tag is associated with a tainted value of an application and an output context of the application that is associated with output from the application that includes the tainted value is determined. A taint processing is a applied to the tainted value in response to the output of the tainted value, the taint processing is compatible with the output context.

Claims (35)

1. A non-transitory processor-readable medium storing code representing instructions that when executed at a processor cause the processor to:

associate a tag with a tainted value of an application, the tag to identify the tainted value as tainted;

determine an output context of the application associated with output from the application during runtime, the output including the tainted value, wherein the output context is one of a plurality of output contexts;

determine a context identifier associated with the output context;

select, using the context identifier, a taint processing from a plurality of taint processings;

apply the selected taint processing to the tainted value in response to the output of the tainted value, wherein the selected taint processing is compatible with the output context; and

output the tainted value with the selected taint processing.

2. The processor-readable medium of claim 1 , wherein the taint processing is an encoding.

3. The processor-readable medium of claim 1 , wherein the tag includes a begin tag and an end tag, the output including the begin tag and the end tag, the tainted value included within the output between the begin tag and the end tag.

4. The processor-readable medium of claim 1 , further storing code representing instructions that when executed at the processor cause the processor to provide the output to a client of the application after the taint processing is applied to the tainted value.

5. The processor-readable medium of claim 1 , wherein:

the tag is included within the output; and

applying the taint processing to the tainted value includes removing the tag from the output.

6. The processor-readable medium of claim 1 , wherein determining the output context includes interpreting the output.

7. A context-sensitive application security system, comprising:

an output context monitor to monitor a current output context of an output of an application during runtime, the output including a tainted value, and to determine a context identifier associated with the output context, wherein the current output context is one of a plurality of output contexts;

a taint processing module to select a taint processing from a plurality of taint processings based on the context identifier, and to apply the taint processing to the tainted value included in the output; and

a delivery module to output the tainted value with the selected taint processing.

8. The system of claim 7 , further comprising an output analysis module to identify the tainted value within the output.

9. The system of claim 7 , wherein the taint processing is an encoding.

10. The system of claim 7 , wherein the output context monitor monitors the current output context of the application based on the output.

11. The system of claim 7 , wherein the taint processing is compatible with the current output context.

12. A context-sensitive application security method, comprising:

determining, by a processor, an output context of output from an application during runtime, the output including a tainted value, wherein the output context is one of a plurality of output contexts;

determining, by the processor, a context identifier associated with the output context;

selecting, by the processor, a taint processing from a plurality of taint processings based on the context identifier;

identifying, by the processor, the tainted value within the output;

applying, by the processor, the taint processing to the tainted value, the taint processing compatible with the output context; and

outputting, by the processor, the tainted value with the selected taint processing.

13. The method of claim 12 , further comprising receiving the output from the application.

14. The method of claim 12 , further comprising monitoring the output context of the application.

15. The method of claim 12 , further comprising providing the output after the taint processing is applied to the tainted value to a client of the application.

16. The method of claim 12 , wherein the identifying is based on a tag associated with the tainted value.

17. The method of claim 12 , wherein the identifying includes locating a begin tag and an end tag within the output, the tainted value included in the output between the begin tag and the end tag.

18. The method of claim 12 , wherein the taint processing is an encoding.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2011
From: CHESS, BRIAN V.; FAY, SEAN PATRICK
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 026993/0670 →
Continuity (1)
Related Publication 20130086687A1 · Apr 4, 2013