发明名称 Mechanism to detect and analyze SQL injection threats
摘要 A vulnerability analysis tool is provided for identifying SQL injection threats. The tool is able to take advantage of the fact that the code for many database applications is located in modules stored within a database. The tool constructs a data flow graph based on all, or a specified subset, of the application code within the database. The tool identifies, within the data flow graph, the nodes that represent values used to construct SQL commands. Paths to those nodes are analyzed to determine whether any SQL injection threats exist.
申请公布号 US7860842(B2) 申请公布日期 2010.12.28
申请号 US20050082280 申请日期 2005.03.16
申请人 ORACLE INTERNATIONAL CORPORATION 发明人 BRONNIKOV DMITRI;WETHERELL CHARLES
分类号 G06F7/00 主分类号 G06F7/00
代理机构 代理人
主权项
地址