×

DETECTING AND LOCALIZING SECURITY VULNERABILITIES IN CLIENT-SERVER APPLICATION

  • US 20110030061A1
  • Filed: 10/12/2010
  • Published: 02/03/2011
  • Est. Priority Date: 07/14/2009
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for analyzing a set of two or more communicating applications comprising a plurality of code fragments, the computer-implemented method comprising:

  • dynamically executing and/or statically analyzing at least one ofa portion of code fragments as part of a first application, anda portion of code fragments as part of a second application,wherein the first application and the second application are communicating at least one of data and control with each other;

    recording a correlation between the code fragments in at least one of the first application and the second application that have been executed and at least one execution characteristic that the code fragments exhibited on execution;

    performing with at least one of a static oracle and a dynamic oracle, an analysis of at least a portion of the code fragments that comprise the first application that have been executed; and

    prioritizing the code fragments in at least one of the first application and the second application based on an evaluation produced by the oracle, and based on the correlation between the code fragments that have been executed and the execution characteristic exhibited by the code fragments.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×