会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明申请
    • System for detecting vulnerabilities in web applications using client-side application interfaces
    • 使用客户端应用程序接口检测Web应用程序中的漏洞的系统
    • US20060195588A1
    • 2006-08-31
    • US11339373
    • 2006-01-24
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • G06F15/16
    • H04L63/1433G06F21/53G06F2221/2119
    • An improved method and apparatus for client-side web application analysis is provided. Client-side web application analysis involves determining and testing, using client-side application interfaces and the like, data input points and analyzing client requests and server responses. In one embodiment, a security vulnerability analyzer is employed to analyze web page content for client-side application files, such as Flash files and Java applets, extract web addresses and data parameters embedded in the client-side application file, and modify the data parameters according to user-defined test criteria. The modified data parameters are transmitted as part of a request to a respective web server used to service the client-side application files. The security vulnerability analyzer analyzes the response from the server to ascertain if there are any security vulnerabilities associated with the interface between the client-side application file and the web server.
    • 提供了一种用于客户端Web应用程序分析的改进方法和装置。 客户端Web应用程序分析涉及使用客户端应用程序接口等来确定和测试数据输入点,并分析客户端请求和服务器响应。 在一个实施例中,使用安全漏洞分析器来分析诸如Flash文件和Java小应用程序之类的客户端应用程序文件的网页内容,提取嵌入在客户端应用程序文件中的Web地址和数据参数,并修改数据参数 根据用户定义的测试标准。 修改的数据参数作为请求的一部分被发送到用于服务客户端应用文件的相应web服务器。 安全漏洞分析器分析来自服务器的响应,以确定是否存在与客户端应用程序文件和Web服务器之间的接口相关联的任何安全漏洞。
    • 3. 发明授权
    • System for detecting vulnerabilities in applications using client-side application interfaces
    • 使用客户端应用程序接口检测应用程序漏洞的系统
    • US08893282B2
    • 2014-11-18
    • US13595829
    • 2012-08-27
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • G06F12/16H04L29/06G06F21/53
    • H04L63/1433G06F21/53G06F2221/2119
    • An improved method and apparatus for client-side application analysis is provided. Client-side application analysis involves determining and testing, using client-side application interfaces and the like, data input points and analyzing client requests and server responses. A security vulnerability analyzer can be employed to analyze content for client-side application files, such as Flash files and Java applets, extract addresses and data parameters embedded in the client-side application file, and modify the data parameters according to user-defined test criteria. The modified data parameters are transmitted as part of a request to a respective server used to service requests from the client-side application files. The security vulnerability analyzer analyzes the response from the server to ascertain if there are any security vulnerabilities associated with the interface between the client-side application file and the server.
    • 提供了一种用于客户端应用程序分析的改进方法和装置。 客户端应用程序分析涉及使用客户端应用程序接口等进行确定和测试,数据输入点和分析客户端请求和服务器响应。 可以使用安全漏洞分析器来分析客户端应用程序文件的内容,例如Flash文件和Java小程序,提取嵌入在客户端应用程序文件中的地址和数据参数,以及根据用户定义的测试修改数据参数 标准 修改的数据参数作为请求的一部分被发送到用于服务来自客户端应用文件的请求的相应服务器。 安全漏洞分析器分析来自服务器的响应,以确定是否存在与客户端应用程序文件和服务器之间的接口相关联的任何安全漏洞。
    • 5. 发明授权
    • System for detecting vulnerabilities in web applications using client-side application interfaces
    • 使用客户端应用程序接口检测Web应用程序中的漏洞的系统
    • US08281401B2
    • 2012-10-02
    • US11339373
    • 2006-01-24
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • G06F12/14
    • H04L63/1433G06F21/53G06F2221/2119
    • An improved method and apparatus for client-side web application analysis is provided. Client-side web application analysis involves determining and testing, using client-side application interfaces and the like, data input points and analyzing client requests and server responses. A security vulnerability analyzer can analyze web page content for client-side application files, such as Flash files and Java applets, extract web addresses and data parameters embedded in the client-side application file, and modify the data parameters according to user-defined test criteria. The modified data parameters are transmitted as part of a request to a respective web server used to service the client-side application files. The security vulnerability analyzer analyzes the response from the server to ascertain if there are any security vulnerabilities associated with the interface between the client-side application file and the web server.
    • 提供了一种用于客户端Web应用程序分析的改进方法和装置。 客户端Web应用程序分析涉及使用客户端应用程序接口等来确定和测试数据输入点,并分析客户端请求和服务器响应。 安全漏洞分析器可以分析客户端应用程序文件(如Flash文件和Java小程序)的网页内容,提取嵌入在客户端应用程序文件中的Web地址和数据参数,并根据用户定义的测试修改数据参数 标准 修改的数据参数作为请求的一部分被发送到用于服务客户端应用文件的相应web服务器。 安全漏洞分析器分析来自服务器的响应,以确定是否存在与客户端应用程序文件和Web服务器之间的接口相关联的任何安全漏洞。
    • 7. 发明申请
    • SYSTEM FOR DETECTING VULNERABILITIES IN WEB APPLICATIONS USING CLIENT-SIDE APPLICATION INTERFACES
    • 使用客户端应用程序界面检测WEB应用程序中的漏洞的系统
    • US20130055403A1
    • 2013-02-28
    • US13595829
    • 2012-08-27
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • G06F21/00
    • H04L63/1433G06F21/53G06F2221/2119
    • An improved method and apparatus for client-side web application analysis is provided. Client-side web application analysis involves determining and testing, using client-side application interfaces and the like, data input points and analyzing client requests and server responses. In one embodiment, a security vulnerability analyzer is employed to analyze web page content for client-side application files, such as Flash files and Java applets, extract web addresses and data parameters embedded in the client-side application file, and modify the data parameters according to user-defined test criteria. The modified data parameters are transmitted as part of a request to a respective web server used to service the client-side application files. The security vulnerability analyzer analyzes the response from the server to ascertain if there are any security vulnerabilities associated with the interface between the client-side application file and the web server.
    • 提供了一种用于客户端Web应用程序分析的改进方法和装置。 客户端Web应用程序分析涉及使用客户端应用程序接口等来确定和测试数据输入点,并分析客户端请求和服务器响应。 在一个实施例中,使用安全漏洞分析器来分析诸如Flash文件和Java小应用程序之类的客户端应用程序文件的网页内容,提取嵌入在客户端应用程序文件中的Web地址和数据参数,并修改数据参数 根据用户定义的测试标准。 修改的数据参数作为请求的一部分被发送到用于服务客户端应用文件的相应web服务器。 安全漏洞分析器分析来自服务器的响应,以确定是否存在与客户端应用程序文件和Web服务器之间的接口相关联的任何安全漏洞。
    • 8. 发明授权
    • Method and apparatus for managing security vulnerability lifecycles
    • 管理安全漏洞生命周期的方法和设备
    • US09239745B1
    • 2016-01-19
    • US11864712
    • 2007-09-28
    • William PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • William PenningtonJeremiah GrossmanRobert StoneSiamak Pazirandeh
    • G06F11/00
    • G06F11/00G06F11/3672G06F21/577H04L63/1433
    • Vulnerability testing of a web application can be done using external testing, wherein an external test system runs with permissions of a user of the web application and interacts with the web application over a network, the external test system might obtain a schedule for a vulnerability test, execute the schedule using the external test system, log at least portions of responses of the web application to interactions of the external test system with the web application, compare portions of the responses to expected possible responses associated with particular possible vulnerabilities of the web application, thereby detecting possible vulnerabilities of the web application and, for at least one detected possible vulnerability, generating a retest script that comprises at least instructions to place the web application in a state at least similar to the state at which the at least one detected possible vulnerability was detected during execution of the schedule and that comprises at least instructions to interact with the web application in an attempt to recreate the detection without requiring reexecution of the schedule.
    • Web应用程序的漏洞测试可以使用外部测试完成,其中外部测试系统以Web应用程序的用户的权限运行,并通过网络与Web应用程序交互,外部测试系统可能会获得漏洞测试的进度 ,使用外部测试系统执行计划,将至少部分Web应用程序的响应记录到外部测试系统与Web应用程序的交互中,将响应中的部分响应与Web应用程序的特定可能漏洞相关联的预期可能响应进行比较 ,从而检测网络应用程序的可能的漏洞,并且对于至少一个检测到的可能的脆弱性,生成重新测试脚本,其包括至少指令以将web应用程序置于至少类似于所述至少一个检测到的可能状态的状态 执行时间表期间检测到漏洞,并包括在l 与Web应用程序交互的东方指令,以尝试重新创建检测,而不需要重新执行日程安排。