发明名称 DIAGNOSTIC DEVICE
摘要 An information analysis device (200) generates and sends a diagnosis request to an application to be diagnosed (318). On the basis of said request, an information gathering device (300) acquires a generated SQL query. The information analysis device (200) checks whether a special character set in an SQL query conditional clause has been escape-processed, thereby determining whether vulnerability exists. Moreover, the information analysis device (200) checks whether the syntax of the SQL query based on the diagnosis request is different from the syntax of an SQL query based on a normal request, and determines whether vulnerability exists. In addition, by checking whether the query based on the diagnosis request is a syntax error, said information analysis device (200) determines whether vulnerability exists.
申请公布号 WO2013065087(A1) 申请公布日期 2013.05.10
申请号 WO2011JP06137 申请日期 2011.11.02
申请人 NST INC.;HISADA, MASAYUKI 发明人 HISADA, MASAYUKI
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址