Invention Grant
- Patent Title: Application aware virtual patching
-
Application No.: US14956129Application Date: 2015-12-01
-
Publication No.: US10083024B2Publication Date: 2018-09-25
- Inventor: Amalkrishnan Chemmany Gopalakrishnan
- Applicant: salesforce.com, inc.
- Applicant Address: US CA San Francisco
- Assignee: SALESFORCE.COM, INC.
- Current Assignee: SALESFORCE.COM, INC.
- Current Assignee Address: US CA San Francisco
- Agency: Sterne, Kessler, Goldstein & Fox P.L.L.C.
- Main IPC: G06F8/65
- IPC: G06F8/65 ; H04L29/08 ; H04L29/06

Abstract:
The technology disclosed relates to thwarting attempts in between software releases to take advantage of security holes in web applications. A virtual patch is a data object comprising an identifier that indicates a relevant local context for the patch and may be created while the application is running. One or more conditions included in the patch are evaluated using data from a service request or from the local context. A patch directive specifies an action to perform when the one or more conditions are satisfied. A virtual patch may be applied to the running application without requiring replacing the application code. Responsive to a request for a web service, a web application may execute code in multiple distinct local contexts such as session management, authorization, and application-specific business logic. The code for each local context may independently retrieve a set of virtual patches relevant to its particular local context.
Public/Granted literature
- US20170153882A1 APPLICATION AWARE VIRTUAL PATCHING Public/Granted day:2017-06-01
Information query