会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 81. 发明申请
    • INCREMENTAL STATIC ANALYSIS
    • 增量静态分析
    • US20120054724A1
    • 2012-03-01
    • US12873219
    • 2010-08-31
    • Daniel KalmanMarco PistoiaGuy PodjarnyOmer TrippOmri Weisman
    • Daniel KalmanMarco PistoiaGuy PodjarnyOmer TrippOmri Weisman
    • G06F9/44
    • G06F8/75G06F11/3604G06F21/577
    • A system, method and computer program product for incremental static analysis, including a change impact analyzer for identifying a changed portion of a computer software (e.g., an application), where the changed portion was changed subsequent to performing a static analysis on the application, a static analysis result invalidator for invalidating any static analysis result that is dependent on the changed portion, and an incremental static analyzer for performing a first incremental static analysis on at least the changed portion, presenting the results of the first incremental static analysis, receiving a request to provide additional information regarding a selected result of the first incremental static analysis, performing, responsive to receiving the request, a second incremental static analysis on any portion of the application to gather the additional information, and presenting results of the second incremental static analysis, thereby providing the additional information regarding the selected result of the first incremental static analysis.
    • 一种用于增量静态分析的系统,方法和计算机程序产品,包括用于识别计算机软件(例如,应用程序)的改变部分的变化影响分析器,其中在对应用执行静态分析之后改变部分被改变, 静态分析结果无效器,用于使依赖于改变的部分的任何静态分析结果无效;以及增量静态分析器,用于至少对所述改变的部分执行第一增量静态分析,呈现第一增量静态分析的结果, 请求提供关于第一增量静态分析的选定结果的附加信息,响应于接收到请求执行,对应用的任何部分进行第二增量静态分析以收集附加信息,以及呈现第二增量静态分析的结果 ,从而提供附加信息rega 选择第一个增量静态分析的结果。
    • 82. 发明授权
    • Transparent digital rights management for extendible content viewers
    • 透明的数字版权管理可扩展内容观众
    • US07171558B1
    • 2007-01-30
    • US09667286
    • 2000-09-22
    • Magda M. MouradJonathan P. MunsonTamer NadeemGiovanni PacificiMarco PistoiaAlaa S. Youssef
    • Magda M. MouradJonathan P. MunsonTamer NadeemGiovanni PacificiMarco PistoiaAlaa S. Youssef
    • H04L9/00
    • G06F21/57G06F21/10
    • A digital rights management system for controlling the distribution of digital content to player applications. The system comprises a verification system, a trusted content handler, and a user interface control. The verification system is provided to validate the integrity of the player applications; and the trusted content handler is used to decrypt content and to transmit the decrypted content to the player applications, and to enforce usage rights associated with the content. The user interface control module is provided to ensure that users of the player applications are not exposed to actions that violate the usage rights. The preferred embodiment of the present invention provides a system that enables existing content viewers, such as Web browsers, document viewers, and Java Virtual Machines running content-viewing applications, with digital rights management capabilities, in a manner that is transparent to the viewer. Extending content viewers with such capabilities enables and facilitates the free exchange of digital content over open networks, such as the Internet, while protecting the rights of content owners, authors, and distributors. This protection is achieved by controlling access to the content and constraining it according to the rights and privileges granted to the user during the content acquisition phase.
    • 数字版权管理系统,用于控制数字内容到玩家应用程序的分发。 系统包括验证系统,可信内容处理程序和用户界面控制。 提供验证系统以验证玩家申请的完整性; 并且可信内容处理程序用于解密内容并将解密的内容传送给播放器应用,并且执行与内容相关联的使用权限。 提供用户界面控制模块以确保玩家应用的用户不会暴露于违反使用权限的动作。 本发明的优选实施例提供了一种系统,其以对观看者透明的方式,使具有数字权限管理功能的现有内容观众(诸如Web浏览器,文档查看器和运行内容观看应用的Java虚拟机)成为可能。 扩展具有此类功能的内容观众能够实现和促进数字内容在互联网等开放网络上的自由交换,同时保护内容所有者,作者和分销商的权利。 该保护通过控制对内容的访问并根据在内容获取阶段中授予用户的权限和特权来约束来实现。
    • 88. 发明授权
    • Detecting security vulnerabilities in web applications
    • 检测Web应用程序中的安全漏洞
    • US08695098B2
    • 2014-04-08
    • US13174628
    • 2011-06-30
    • Marco PistoiaOri SegalOmer Tripp
    • Marco PistoiaOri SegalOmer Tripp
    • G06F11/00
    • G06F21/577H04L63/1433
    • Method to detect security vulnerabilities includes: interacting with a web application during its execution to identify a web page exposed by the web application; statically analyzing the web page to identify a parameter within the web page that is constrained by a client-side validation measure and that is to be sent to the web application; determining a server-side validation measure to be applied to the parameter in view of the constraint placed upon the parameter by the client-side validation measure; statically analyzing the web application to identify a location within the web application where the parameter is input into the web application; determining whether the parameter is constrained by the server-side validation measure prior to the parameter being used in a security-sensitive operation; and identifying the parameter as a security vulnerability.
    • 检测安全漏洞的方法包括:在执行期间与Web应用程序进行交互以识别Web应用程序公开的网页; 静态地分析网页以识别受到客户端验证措施约束并且要发送到Web应用程序的网页内的参数; 鉴于通过客户端验证措施对参数的约束,确定要应用于参数的服务器端验证度量; 静态分析Web应用程序以识别Web应用程序中将参数输入到Web应用程序中的位置; 在参数在安全敏感操作中使用之前,确定参数是否受到服务器端验证度量的约束; 并将该参数识别为安全漏洞。