首页> 外国专利> AUTOMATED FUZZING BASED ON ANALYSIS OF APPLICATION EXECUTION FLOW

AUTOMATED FUZZING BASED ON ANALYSIS OF APPLICATION EXECUTION FLOW

机译:基于应用执行流分析的自动模糊

摘要

Described herein is a system and method for identifying a vulnerability of an application (e.g., web application). A message comprising a request and associated execution flow of the application in response to the request is received. The message is analyzed to determine whether the execution flow includes a function pre-defined as interesting. In response to determining that the execution flow includes the function pre-defined as interesting, a determination is made that the function pre-defined as interesting comprises a vulnerability of the application. In response to determining that the function pre-defined as interesting comprises a vulnerability of the application, an action is taken with respect to the vulnerability. The action can include, for example, providing information regarding the identified vulnerability and/or blocking execution of particular code of the application.
机译:本文描述了用于识别应用程序(例如,Web应用程序)的漏洞的系统和方法。接收包括请求和响应于该请求的应用程序的相关执行流程的消息。分析消息以确定执行流是否包括预定义为有趣的功能。响应于确定执行流程包括预定义为有趣的功能,确定预定义为有趣的功能包括应用程序的漏洞。响应于确定预定义为感兴趣的功能包括应用程序的漏洞,针对该漏洞采取措施。该动作可以包括例如提供关于所识别的漏洞的信息和/或阻止执行应用的特定代码。

著录项

  • 公开/公告号WO2019125737A1

    专利类型

  • 公开/公告日2019-06-27

    原文格式PDF

  • 申请/专利权人 MICROSOFT TECHNOLOGY LICENSING LLC;

    申请/专利号WO2018US63503

  • 发明设计人 HENDRICKX MICHAEL;

    申请日2018-11-30

  • 分类号G06F21/14;G06F21/12;G06F21/57;

  • 国家 WO

  • 入库时间 2022-08-21 11:54:09

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号