发明名称 Apparatus and method for detecting, prioritizing and fixing security defects and compliance violations in SAP® ABAP™ code
摘要 A static code analysis (SCA) tool, apparatus and method detects, prioritizes and fixes security defects and compliance violations in SAP® ABAP™ code. The code, meta information and computer system configuration settings are transformed into an interchangeable format, and parsed into an execution model. A rules engine is applied to the execution model to identify security and compliance violations. The rules engine may include information about critical database tables and critical SAP standard functions, and the step of applying the rules engine to the execution model may include the calculation of specific business risks or whether a technical defect has a business-relevant impact. In particular, an asset flow analysis may be used to determine whether critical business data is no longer protected by the computer system. Such critical business data may include credit or debit card numbers, financial data or personal data.
申请公布号 US8402547(B2) 申请公布日期 2013.03.19
申请号 US201113046257 申请日期 2011.03.11
申请人 WIEGENSTEIN ANDREAS;SCHUMACHER MARKUS;JIA XU;VIRTUAL FORGE GMBH 发明人 WIEGENSTEIN ANDREAS;SCHUMACHER MARKUS;JIA XU
分类号 G06F11/30;G06F9/44 主分类号 G06F11/30
代理机构 代理人
主权项
地址