Invention Grant
- Patent Title: Patch validation via replay and remediation verification
-
Application No.: US15177202Application Date: 2016-06-08
-
Publication No.: US09727738B1Publication Date: 2017-08-08
- Inventor: Mark G. Kuhr , Patrick Wardle
- Applicant: SYNACK, INC.
- Applicant Address: US CA Redwood City
- Assignee: Synack, Inc.
- Current Assignee: Synack, Inc.
- Current Assignee Address: US CA Redwood City
- Agency: Hickman Palermo Becker Bingham LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; G06F21/57 ; H04L29/08 ; H04L29/06 ; G06F21/55

Abstract:
A method and apparatus for patch validation via replay and remediation verification is provided. A method comprises: receiving, from a researcher computer, a report of a potential vulnerability that the researcher computer identified in a computer program application that the researcher computer accessed via a first web browser, the report comprising a record of actions performed by the researcher computer, a first outcome of the actions, and Document Object Model (DOM) events that the application outputted when the record of actions was generated; automatically generating an executable script from the record of actions, wherein the executable script, when executed, causes the web browser to perform the actions that are recorded in the record of actions; verifying the report of the potential vulnerability by executing the executable script in a second web browser and determining that a second outcome of the actions matches the first outcome that was recorded in the record of actions; determining that the first outcome of the actions is associated with a security vulnerability.
Information query