发明名称 DETECTING STORED CROSS-SITE SCRIPTING VULNERABILITIES IN WEB APPLICATIONS
摘要 A system for detecting security vulnerabilities in web applications, the system including, a black-box tester configured to provide a payload to a web application during a first interaction with the web application at a computer server, where the payload includes a payload instruction and an identifier, and an execution engine configured to detect the identifier within the payload received during an interaction with the web application subsequent to the first interaction, and determine, responsive to detecting the identifier within the payload, whether the payload instruction underwent a security check prior to execution of the payload instruction.
申请公布号 US2017024567(A1) 申请公布日期 2017.01.26
申请号 US201615283664 申请日期 2016.10.03
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 AMIT YAIR;LANDA ALEXANDER;TRIPP OMER
分类号 G06F21/57;H04L29/06 主分类号 G06F21/57
代理机构 代理人
主权项
地址 ARMONK NY US