- 专利标题: Rest API Scanning for Security Testing
-
申请号: US18380411申请日: 2023-10-16
-
公开(公告)号: US20240064167A1公开(公告)日: 2024-02-22
- 发明人: Ganesh Nikam , Akash Shah
- 申请人: Qualys, Inc.
- 申请人地址: US CA Foster City
- 专利权人: Qualys, Inc.
- 当前专利权人: Qualys, Inc.
- 当前专利权人地址: US CA Foster City
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; G06F16/951 ; G06F9/54 ; G06F9/445 ; H04L67/133
摘要:
Methods and systems for securing an application programming interface (API) are presented. The method comprises: receiving API workflow data associated with an API testing tool and generating a scan configuration file using the API workflow data; crawling the collection of API requests by identifying and retrieving a link associated with the collection of API requests; and crawling the link to generate a crawled link response. The method also includes executing one or more vulnerability tests on the crawled link response including applying at least one passive detection rule to the crawled link response and fuzzing the link. The fuzzed link may be transmitted in a request to an application server following which scan data indicative of at least one vulnerability associated with a response from the application server may be generated. The scan data may be used to generate a vulnerability report.
信息查询