×

Runtime protection of web services

  • US 10,243,987 B2
  • Filed: 01/23/2018
  • Issued: 03/26/2019
  • Est. Priority Date: 06/18/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computer program product for protecting a runtime Web service application, the computer program product comprising a computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code configured to perform a method, the method comprising:

  • enabling the Web service application to log its operation and create an execution trace;

    identifying a trace point vulnerability using one or more data payloads and one or more security rules;

    identifying a candidate trace point operation associated with the trace point vulnerability;

    computing a supplementary candidate operation based on the existing trace point operation and the trace point vulnerability; and

    further enabling the Web service application with the supplementary candidate operation, wherein each data payload comprises an example set of data, and wherein the identifying the candidate trace point operation associated with the trace point vulnerability is performed by checking data flow through an application and an instrumented version of the application using one of the one or more data payloads and specifying a security rule to define the data flow, and wherein the candidate trace point operation is an operation for which a payload value has been rejected by a validator or has been sanitized by a sanitizer, and wherein the trace point vulnerability is reported, and wherein a vulnerability detector performs further vulnerabilities testing after the Web service application has been further instrumented with one or more supplementary candidate operations.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×