发明名称 CROSS-SITE SCRIPTING DETECTION METHOD
摘要 The cross-site scripting detection method (2700) inputs a web page application program into a virtual machine. Output of the virtual machine produces bytecode and a control flow graph. A state transition graph encoder uses the bytecode and control flow graph to produce transition, initial, and property (Τ,Ι,Ρ) state information. The Τ,Ι,Ρ state information is then parsed by a parser. Output of the parser is fed to a reachability verifier that produces a verified flag (OK) or alternatively a positive counter-example (CEX). The CEX is transformed into the web page application program and fed as HTML to a browser which checks for feasibility of a XSS find. A feasibility indication suggests a true positive find of the XSS malicious code. An infeasibility indication suggests a false positive find upon which, via feedback of the infeasibility indication, the reachability verifier is retuned to refine the solution.
申请公布号 WO2016168428(A1) 申请公布日期 2016.10.20
申请号 WO2016US27482 申请日期 2016.04.14
申请人 QATAR FOUNDATION FOR EDUCATION, SCIENCE AND COMMUNITY DEVELOPMENT 发明人 SAKALLAH, Karem A.;SANS, Thierry;HAZBOUN, Sherin
分类号 G06F21/55;G06F21/56 主分类号 G06F21/55
代理机构 代理人
主权项
地址