会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明申请
    • VULNERABILITY-DIAGNOSIS DEVICE
    • 脆弱性诊断装置
    • US20130227698A1
    • 2013-08-29
    • US13884444
    • 2011-11-10
    • Tomohiro TaniguchiHideyuki MajimaTakahiro TokueTakashi OhkusaMasashi TabataShintaro Ueda
    • Tomohiro TaniguchiHideyuki MajimaTakahiro TokueTakashi OhkusaMasashi TabataShintaro Ueda
    • H04L29/06
    • H04L63/1433G06F21/554G06F21/577G06F21/6227
    • To diagnose vulnerabilities such as SQL injection, even for web-server devices that change the content of responses to requests in accordance with prescribed conditions. A normal-response collection means (10) transmits a normal request (REQN), accompanied by a registered user ID and password, a plurality of times. Said normal-response collection means (10) receives a plurality of responses (RESN) (hereafter “normal responses”) from a web server in response to the normal requests. A common-region extraction means (12) extracts a common region from the plurality of normal responses. An abnormal-response collection means (18) performs SQL injection on the web server, receives the response (RESA) (hereafter “abnormal response”), and records same in a storage unit (16). A determination means (14) determines that the web server has a vulnerability if the normal responses and the abnormal response are the same in the common region.
    • 要诊断诸如SQL注入之类的漏洞,即使是根据规定条件更改请求响应内容的Web服务器设备。 正常响应收集装置(10)多次发送附有注册用户ID和密码的正常请求(REQN)。 所述正常响应收集装置(10)响应于正常请求从web服务器接收多个响应(RESN)(以下称为“正常响应”)。 公共区域提取装置(12)从多个正常响应中提取公共区域。 异常响应收集装置(18)在Web服务器上执行SQL注入,接收响应(RESA)(以下称为“异常响应”),并将其记录在存储单元(16)中。 如果正常响应和异常响应在公共区域中相同,则确定装置(14)确定web服务器具有脆弱性。
    • 2. 发明授权
    • Vulnerability-diagnosis device
    • 漏洞诊断设备
    • US08918887B2
    • 2014-12-23
    • US13884444
    • 2011-11-10
    • Tomohiro TaniguchiHideyuki MajimaTakahiro TokueTakashi OhkusaMasashi TabataShintaro Ueda
    • Tomohiro TaniguchiHideyuki MajimaTakahiro TokueTakashi OhkusaMasashi TabataShintaro Ueda
    • G06F21/00H04L29/06G06F21/55G06F21/62G06F21/57
    • H04L63/1433G06F21/554G06F21/577G06F21/6227
    • To diagnose vulnerabilities such as SQL injection, even for web-server devices that change the content of responses to requests in accordance with prescribed conditions. A normal-response collection means (10) transmits a normal request (REQN), accompanied by a registered user ID and password, a plurality of times. Said normal-response collection means (10) receives a plurality of responses (RESN) (hereafter “normal responses”) from a web server in response to the normal requests. A common-region extraction means (12) extracts a common region from the plurality of normal responses. An abnormal-response collection means (18) performs SQL injection on the web server, receives the response (RESA) (hereafter “abnormal response”), and records same in a storage unit (16). A determination means (14) determines that the web server has a vulnerability if the normal responses and the abnormal response are the same in the common region.
    • 要诊断诸如SQL注入之类的漏洞,即使是根据规定条件更改响应请求的Web服务器设备。 正常响应收集装置(10)多次发送附有注册用户ID和密码的正常请求(REQN)。 所述正常响应收集装置(10)响应于正常请求从web服务器接收多个响应(RESN)(以下称为“正常响应”)。 公共区域提取装置(12)从多个正常响应中提取公共区域。 异常响应收集装置(18)在Web服务器上执行SQL注入,接收响应(RESA)(以下称为“异常响应”),并将其记录在存储单元(16)中。 如果正常响应和异常响应在公共区域中相同,则确定装置(14)确定web服务器具有脆弱性。