The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 06, 2018

Filed:

Dec. 24, 2015
Applicant:

Checkmarx Ltd., Ramat Gan, IL;

Inventors:

Shimon Eshkenazi, Bat Yam, IL;

Maty Siman, Tel Aviv, IL;

Alexander Roichman, Petach-Tikva, IL;

Assignee:

CHECKMARX LTD., Ramat Gan, IL;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/51 (2013.01); G06F 21/52 (2013.01); G06F 8/75 (2018.01); G06F 9/32 (2018.01); G06F 9/445 (2018.01); G06F 21/12 (2013.01);
U.S. Cl.
CPC ...
G06F 21/51 (2013.01); G06F 8/75 (2013.01); G06F 9/328 (2013.01); G06F 9/44568 (2013.01); G06F 21/52 (2013.01); G06F 21/12 (2013.01);
Abstract

A method for runtime self-protection of an application program includes, before running the application program, identifying input and output points in runtime code () of the program. The input points are instrumented so as to cause the program to sense and cache potentially malicious inputs to the program. The output points are instrumented so as to cause the program to detect outputs from the program corresponding to the cached inputs. While running the application program, upon detecting, at an instrumented output point, an output corresponding to a cached input, a vulnerability of a target of the output to the cached input is evaluated. A protective action is invoked upon determining that the output is potentially vulnerable to the cached input.


Find Patent Forward Citations

Loading…