The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 26, 2007

Filed:

Mar. 20, 2003
Applicants:

Eran Reshef, Tel-Aviv, IL;

Yuval El-hanany, Tel-Aviv, IL;

Gil Raanan, Zoran, IL;

Tom Tsarfati, Tel-Aviv, IL;

Inventors:

Eran Reshef, Tel-Aviv, IL;

Yuval El-Hanany, Tel-Aviv, IL;

Gil Raanan, Zoran, IL;

Tom Tsarfati, Tel-Aviv, IL;

Assignee:

Watchfire Corporation, Kanata, Ontario, CA;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/30 (2006.01);
U.S. Cl.
CPC ...
Abstract

A method for detecting security vulnerabilities in a web application includes analyzing the client requests and server responses resulting therefrom in order to discover pre-defined elements of the application's interface with external clients and the attributes of these elements. The client requests are then mutated based on a pre-defined set of mutation rules to thereby generate exploits unique to the application. The web application is attacked using the exploits and the results of the attack are evaluated for anomalous application activity.


Find Patent Forward Citations

Loading…