- 专利标题: System and method for application software security and auditing
-
申请号: US16445431申请日: 2019-06-19
-
公开(公告)号: US10992715B2公开(公告)日: 2021-04-27
- 发明人: Michael Feiertag , Garrett Held , Andre Eriksson , William Saar
- 申请人: Rapid7, Inc.
- 申请人地址: US MA Boston
- 专利权人: Rapid7, Inc.
- 当前专利权人: Rapid7, Inc.
- 当前专利权人地址: US MA Boston
- 代理商 Ashwin Anand
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F8/61 ; G06F21/57 ; G06F21/62
摘要:
A system and method for application software security and auditing are disclosed. A particular embodiment includes an application security management system configured to: instrument one or more data input and output points of an application for one or more instances of data identified as sensitive data, access one or more policies corresponding to the one or more instances of the sensitive data, trace the one or more instances of the sensitive data through the application in association with the one or more policies, and generate an audit of each instance of the sensitive data indicating a route from which the sensitive data is accessed, to where the sensitive data is written, and where the sensitive data surfaces in the application.
公开/授权文献
信息查询