Invention Grant
- Patent Title: Automatic synthesis of unit tests for security testing
- Patent Title (中): 自动合成单元测试用于安全测试
-
Application No.: US13367633Application Date: 2012-02-07
-
Publication No.: US08856935B2Publication Date: 2014-10-07
- Inventor: Daniel Kalman , Ory Segal , Omer Tripp , Omri Weisman
- Applicant: Daniel Kalman , Ory Segal , Omer Tripp , Omri Weisman
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Cuenot, Forsythe & Kim, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/00

Abstract:
Performing security analysis on a computer program under test (CPUT). The CPUT can be analyzed to identify data pertinent to potential security vulnerabilities of the CPUT. At least a first unit test configured to test a particular unit of program code within the CPUT can be automatically synthesized. The first unit test can be configured to initialize at least one parameter used by the particular unit of program code within the CPUT, and can be provided at least a first test payload configured to exploit at least one potential security vulnerability of the CPUT. The first unit test can be dynamically processed to communicate the first test payload to the particular unit of program code within the CPUT. Whether the first test payload exploits an actual security vulnerability of the CPUT can be determined, and a security analysis report can be output.
Public/Granted literature
- US20130205398A1 AUTOMATIC SYNTHESIS OF UNIT TESTS FOR SECURITY TESTING Public/Granted day:2013-08-08
Information query