发明名称 SYSTEM AND A METHOD FOR AUTOMATICALLY DETECTING SECURITY VULNERABILITIES IN CLIENT-SERVER APPLICATIONS
摘要 A method for automatically detecting security vulnerabilities in a client-server application where a client is connected to a server. The method is implemented by a computer having a processor and a software program stored on a non-transitory computer readable medium. The method includes automatically extracting, with the software program at the client, a description of one or more validation checks on inputs performed by the client. The method also includes analyzing the server, with the software program by using the one or more validation checks on inputs performed by the client, to determine whether the server is not performing validation checks that the server must be performing. The method further includes determining that security vulnerabilities in the client-server application exist when the server is not performing validation checks that the server must be performing. A method further proposes preventing parameter tampering attacks on a running client-server application by enforcing the one or more validation checks on inputs performed by the client on each input that is submitted to the server.
申请公布号 US2013091578(A1) 申请公布日期 2013.04.11
申请号 US201213627928 申请日期 2012.09.26
申请人 THE BOARD OF TRUSTEES OF THE UNIVERSITY OF ILINOIS;THE BOARD OF TRUSTEES OF THE UNIVERSITY OF ILLINOIS 发明人 BISHT PRITHVI;HINRICHS TIMOTHY;VENKATAKRISHNAN VENKATESAN NATARAJAN
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址