- 专利标题: Persistent cross-site scripting vulnerability detection
-
申请号: US16353795申请日: 2019-03-14
-
公开(公告)号: US11005877B2公开(公告)日: 2021-05-11
- 发明人: Emanuel Bronshtein , Roee Hay , Sagi Kedmi
- 申请人: HCL Technologies Limited
- 申请人地址: IN New Delhi
- 专利权人: HCL Technologies Limited
- 当前专利权人: HCL Technologies Limited
- 当前专利权人地址: IN New Delhi
- 代理机构: Brooks Kushman P.C.
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
Various techniques for detecting a persistent cross-site scripting vulnerability are described herein. In one example, a method includes detecting, via the processor, a read operation executed on a resource using an instrumentation mechanism and returning, via the processor, a malicious script in response to the read operation. The method also includes detecting, via the processor, a write operation executed on the resource using the instrumentation mechanism and detecting, via the processor, a script operation executed by the malicious script that results in resource data being sent to an external computing device from a client device. Furthermore, the method includes receiving, via the processor, metadata indicating the execution of the read operation, the write operation, and the script operation.
公开/授权文献
- US20190215333A1 PERSISTENT CROSS-SITE SCRIPTING VULNERABILITY DETECTION 公开/授权日:2019-07-11
信息查询