IP Library Granted Patent US 9,501,650
Granted Patent B2
US 9,501,650 · App. 14/846,462 · Granted Nov 22, 2016

Application security testing

Inventors: Brian V. Chess (Palo Alto, CA); Iftach Ragoler (Alpharetta, GA); Philip Edward Hamer (Alpharetta, GA); Russell Andrew Spitler (San Francisco, CA); Sean Patrick Fay (San Francisco, CA); Prajakta Subbash Jagdale (Alpharetta, GA)
Assignee: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
G06F21/577G06F21/52H04L63/1433G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,501,650
App. No.
14/846,462
Granted
Nov 22, 2016
Kind
B2
Abstract

The present disclosure provides a system that includes a server hosting an application under test (AUT), an observer configured to monitor instructions executed by the AUT, and a computing device communicatively coupled to the AUT and the observer through a common communication channel. The computing device may be configured to send an application request to the AUT, wherein the application request is configured to expose a potential vulnerability of the AUT. The computing device may receive an application response from the AUT in accordance with the AUT's programming. The computing device may send a service request to the observer, and receive a service response from the observer that contains information corresponding to the instructions executed by the AUT due to the application request, information about the AUT, or information about a server hosting the AUT.

Claims (53)

1. A system, comprising:

a server hosting an application under test (AUT);

an observer to i) monitor instructions executed by the AUT, and ii) communicate with a computing device, at least in part, by adding a custom header to an application response; and

the computing device communicatively coupled to the AUT and the observer through a common communication channel, the computing device comprising a processor and a memory device for storing computer-readable instructions configured to direct the processor to:

send an application request to the AUT, wherein the application request is configured to expose a potential vulnerability of the AUT;

receive the application response from the AUT in accordance with the AUT's programming;

send a service request to the observer; and

receive a service response from the observer, the service response containing information corresponding to the instructions executed by the AUT due to the application request, information about the AUT, or information about a server hosting the AUT.

2. The system of claim 1 , the memory device comprising computer-readable instructions configured to direct the processor to receive trace information from the observer, the trace information comprising a plurality of vulnerability trace nodes, each vulnerability trace node containing code locations corresponding to a vulnerability detected by the observer.

3. The system of claim 2 , the memory device comprising computer-readable instructions configured to direct the processor to group the plurality of vulnerability trace nodes based on the vulnerability trace nodes containing the same code locations.

4. The system of claim 1 , wherein the observer is configured to monitor the AUT to identify new uniform resource locators (URLs) that are generated dynamically during runtime of the AUT, and return an update field in a header of the application response, the update field configured to inform the computing device that an attack surface of the AUT has changed.

5. The system of claim 1 , wherein the observer is configured to:

receive a request from the computing device and analyze a header of the request;

identify the request as the application request or the service request based on the analysis of the header;

pass the application request to the AUT; and

process the service request without passing the service request to the AUT.

6. A method, comprising:

sending an application request to an application under test (AUT), wherein the application request is configured to expose a potential vulnerability of the AUT;

receiving an application response from the AUT in accordance with the AUT's programming, the application response including a custom header that was added by an observer that monitors instructions executed by the AUT;

sending a service request to the observer; and

receiving a service response from the observer, the service response containing information corresponding to instructions executed by the AUT due to the application request, information about the AUT, or information about a server hosting the AUT;

wherein the application request, application response, service request, and service response are communicated over a same network channel.

7. The method of claim 6 , comprising receiving a file-not-found header in the application response, the file-not-found header added to the application response by the observer to indicate a file-not-found error generated by the AUT.

8. The method of claim 6 , wherein the service request is a trace service request, the method comprising receiving a stack trace in a body of the service response received from the observer.

9. The method of claim 6 , comprising receiving a vulnerability trace node in the body of the service response, wherein the vulnerability trace node identifies a vulnerability detected by the observer.

10. The method of claim 6 , wherein the service request is an attack surface service request, the method comprising receiving information about the attack surface of the AUT in a body of the service response, the attack surface comprising static URLs and dynamic URLs that are generated by the AUT during runtime.

11. The method of claim 6 , further comprising:

receiving, by the observer, a request and analyzes a header of the request;

identifying, by the observer, the request as the application request or the service request based on the analysis of the header;

passing, by the observer, the application request to the AUT; and

processing, by the observer, the service request without passing the service request to the AUT.

12. The method of claim 6 , wherein the trace includes trace information comprising a plurality of vulnerability trace nodes, each vulnerability trace node containing code locations corresponding to a vulnerability detected by the observer.

13. The method of claim 6 , further comprising:

receiving trace information from the observer, the trace information comprising a plurality of vulnerability trace nodes, each vulnerability trace node containing code locations corresponding to a vulnerability detected by the observer.

14. The method of claim 13 , further comprising:

grouping the plurality of vulnerability trace nodes based on the vulnerability trace nodes containing the same code locations.

15. A non-transitory, computer readable medium, comprising code configured to direct a processor to:

send an application request to an application under test (AUT), wherein the application request is configured to expose a potential vulnerability of the AUT;

receive an application response from the AUT in accordance with the AUT's programming, the application response including a custom header that was added by an observer that monitors instructions executed by the AUT;

send a service request to the observer; and

receive a service response from the observer, the service response containing information corresponding to instructions executed by the AUT due to the application request, information about the AUT, or information about a server hosting the AUT;

wherein the application request, application response, service request, and service response are communicated over a same network channel.

16. The non-transitory, computer readable medium of claim 15 , comprising code configured to direct the processor to add a request ID to a header of the application request that uniquely identifies the application request, wherein the service response received from the observer includes the request ID.

17. The non-transitory, computer readable medium of claim 15 , wherein the service response includes a database trace node that includes information corresponding to a database query performed by the AUT as a result of the application request.

18. The non-transitory, computer readable medium of claim 15 , wherein the observer:

receives a request and analyzes a header of the request;

identifies the request as the application request or the service request based on the analysis of the header;

passes the application request to the AUT; and

processes the service request without passing the service request to the AUT.

19. The non-transitory, computer readable medium of claim 15 , wherein:

the service request is an attack surface service request, and

information about the attack surface of the AUT is included in the body of the service response, and the attack surface comprises static URLs and dynamic URLs that are generated by the AUT during runtime.

20. The non-transitory, computer readable medium of claim 15 , comprising code configured to direct the processor to receive trace information from the observer, the trace information comprising a plurality of vulnerability trace nodes, each vulnerability trace node containing code locations corresponding to a vulnerability detected by the observer.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2016
From: CHESS, BRIAN V.; RAGOLER, IFTACH; HAMER, PHILIP EDWARD; SPITLER, RUSSELL ANDREW; FAY, SEAN PATRICK; JAGDALE, PRAJAKTA SUBBASH
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 039139/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
Continuity (2)
Continuation 14116000
Related Publication 20150379273A1 · Dec 31, 2015