- 专利标题: Site independent methods for deriving contextually tailored security vulnerability corrections for hardening solution stacks
-
申请号: US14485645申请日: 2014-09-12
-
公开(公告)号: US09742791B2公开(公告)日: 2017-08-22
- 发明人: Michael Borohovski , Ainsley K. Braun , Angel Irizarry , Benjamin D. Sedat
- 申请人: Tinfoil Security, Inc.
- 申请人地址: US CA Mountain View
- 专利权人: Tinfoil Security, Inc.
- 当前专利权人: Tinfoil Security, Inc.
- 当前专利权人地址: US CA Mountain View
- 代理机构: Fenwick & West LLP
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F17/22 ; G06F21/57
摘要:
In auditing a target Web site for security exposures, site specific remediation reports are generated to provide instructional data tailored to components of the Web server solution stack as determined by the auditing computer system. Stack and component identification is performed in a site independent manner based on an analysis of Web page data retrieved by the auditing computer system. Informational aspects of the received data are recognized, enabling further identification of component implementation aspects. Based on the informational and implementation aspects, site, solution stack, and component specific security audit tests are executed against the target Web site. Audit identified security exposures are recorded in correspondence with site, solution stack, and component implementation specific remediation instruction data.
公开/授权文献
信息查询