会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 4. 发明授权
    • Method and apparatus for managing security vulnerability lifecycles
    • 管理安全漏洞生命周期的方法和设备
    • US09239745B1
    • 2016-01-19
    • US11864712
    • 2007-09-28
    • William PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • William PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • G06F11/00
    • G06F11/00G06F11/3672G06F21/577H04L63/1433
    • Vulnerability testing of a web application can be done using external testing, wherein an external test system runs with permissions of a user of the web application and interacts with the web application over a network, the external test system might obtain a schedule for a vulnerability test, execute the schedule using the external test system, log at least portions of responses of the web application to interactions of the external test system with the web application, compare portions of the responses to expected possible responses associated with particular possible vulnerabilities of the web application, thereby detecting possible vulnerabilities of the web application and, for at least one detected possible vulnerability, generating a retest script that comprises at least instructions to place the web application in a state at least similar to the state at which the at least one detected possible vulnerability was detected during execution of the schedule and that comprises at least instructions to interact with the web application in an attempt to recreate the detection without requiring reexecution of the schedule.
    • Web应用程序的漏洞测试可以使用外部测试完成,其中外部测试系统以Web应用程序的用户的权限运行,并通过网络与Web应用程序交互,外部测试系统可能会获得漏洞测试的进度 ,使用外部测试系统执行计划,将至少部分Web应用程序的响应记录到外部测试系统与Web应用程序的交互中,将响应中的部分响应与Web应用程序的特定可能漏洞相关联的预期可能响应进行比较 ,从而检测网络应用程序的可能的漏洞,并且对于至少一个检测到的可能的脆弱性,生成重新测试脚本,其包括至少指令以将web应用程序置于至少类似于所述至少一个检测到的可能状态的状态 执行时间表期间检测到漏洞,并包括在l 与Web应用程序交互的东方指令,以尝试重新创建检测,而不需要重新执行日程安排。