首页> 外国专利> Security testing framework including virtualized server-side platform

Security testing framework including virtualized server-side platform

机译:安全测试框架,包括虚拟化的服务器端平台

摘要

A web application security testing framework includes a HTTP browser engine replaying recorded sessions to identify candidate traces indicative of attack. A mutation engine changes values in the attack candidate traces to generate additional traces posed against a virtualized server-side platform. The virtualized server-side platform creates snapshots of application state for testing, avoiding permanent damage to application persistence. The virtualized server-side platform includes persistence monitoring sensors (e.g., at connectors to the database or file system) for detecting vulnerability classes including Cross-Site Request Forgery (CSRF) and SQL injection attacks. For remote command execution attack detection, a server-side vulnerability validation interface records strings passed to code generating application program interfaces (APIs). For possible Cross-Site Scripting (XSS) attacks, the mutation engine may detect HTTP responses for examination of generated web code, and the HTTP browser may be extended to include a vulnerability validation API that is automatically called by successfully injected attack payloads.
机译:Web应用程序安全性测试框架包括一个HTTP浏览器引擎,该引擎重播记录的会话以识别表示攻击的候选跟踪。变异引擎更改攻击候选跟踪中的值,以生成针对虚拟化服务器端平台的其他跟踪。虚拟化的服务器端平台可创建应用程序状态快照以进行测试,从而避免对应用程序持久性造成永久性损害。虚拟化的服务器端平台包括持久性监视传感器(例如,在数据库或文件系统的连接器处),用于检测包括跨站点请求伪造(CSRF)和SQL注入攻击在内的漏洞类别。对于远程命令执行攻击检测,服务器端漏洞验证接口记录传递给代码生成应用程序接口(API)的字符串。对于可能的跨站点脚本(XSS)攻击,变异引擎可以检测HTTP响应以检查生成的Web代码,并且HTTP浏览器可以扩展为包括漏洞验证API,该API可以由成功注入的攻击有效负载自动调用。

著录项

  • 公开/公告号US10503910B2

    专利类型

  • 公开/公告日2019-12-10

    原文格式PDF

  • 申请/专利权人 SAP SE;

    申请/专利号US201715615603

  • 发明设计人 MARTIN JOHNS;

    申请日2017-06-06

  • 分类号G06F21/57;G06F21/55;

  • 国家 US

  • 入库时间 2022-08-21 11:23:53

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号