首页> 外国专利> Systems and methods of soft patching security vulnerabilities

Systems and methods of soft patching security vulnerabilities

机译:软补丁安全漏洞的系统和方法

摘要

A method and apparatus for soft patching security vulnerabilities is provided. A method comprises: receiving, from a first researcher computer, a report of a security vulnerability that was identified in a computer program application that the first researcher computer accessed via a first web browser, the report comprising a record of actions performed by the first researcher computer and Document Object Model (DOM) events that the application outputted when the record of actions was generated; automatically generating a detection script comprising a set of requests associated with the security vulnerability from the record of actions, wherein the detection script, when executed by an intermediary computer that is between a network and a second researcher computer, causes the intermediary computer to detect that the second researcher computer is performing actions that are recorded in the record of actions in the application accessed via the first web browser, and, in response, causing the intermediary computer to drop at least some network traffic that is forwarded in the network toward the second researcher computer; sending the detection script to the intermediary computer.
机译:提供了一种用于软修补安全漏洞的方法和装置。一种方法包括:从第一研究者计算机接收第一研究者计算机经由第一网络浏览器访问的在计算机程序应用中识别出的安全漏洞的报告,该报告包括由第一研究者执行的动作的记录。生成动作记录时应用程序输出的计算机和文档对象模型(DOM)事件;从动作记录中自动生成包含与安全漏洞相关的一组请求的检测脚本,其中,当检测脚本由网络和第二研究人员计算机之间的中间计算机执行时,该中间脚本会检测到该脚本第二研究人员计算机正在执行通过第一Web浏览器访问的应用程序中的操作记录中记录的操作,并作为响应,使中间计算机丢弃在网络中转发给第二计算机的至少一些网络流量。研究人员计算机;将检测脚本发送到中间计算机。

著录项

  • 公开/公告号US9660870B1

    专利类型

  • 公开/公告日2017-05-23

    原文格式PDF

  • 申请/专利权人 SYNACK INC.;

    申请/专利号US201615177209

  • 发明设计人 MARK G. KUHR;PATRICK WARDLE;

    申请日2016-06-08

  • 分类号G06F15/173;H04L12/24;

  • 国家 US

  • 入库时间 2022-08-21 13:44:13

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号