发明名称 PERSISTENT CROSS-SITE SCRIPTING VULNERABILITY DETECTION
摘要 A system and program product are described herein for various techniques for detecting a persistent cross-site scripting vulnerability are described herein. In one example, the techniques include detecting, via the processor, a read operation executed on a resource using an instrumentation mechanism and returning, via the processor, a malicious script in response to the read operation. The techniques also include detecting, via the processor, a write operation executed on the resource using the instrumentation mechanism and detecting, via the processor, a script operation executed by the malicious script that results in resource data being sent to an external computing device from a client device. Furthermore, the techniques include receiving, via the processor, metadata indicating the execution of the read operation, the write operation, and the script operation.
申请公布号 US2016149946(A1) 申请公布日期 2016.05.26
申请号 US201414552570 申请日期 2014.11.25
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 Bronshtein Emanuel;Hay Roee;Kedmi Sagi
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址 Armonk NY US