Discovery of application vulnerabilities involving multiple execution flows
Abstract
Methods and systems for security analysis of an application are disclosed. In accordance with one method, a flow-insensitive analysis is conducted on the application to obtain a set of potential vulnerabilities in the application. For each of the potential vulnerabilities, a relevant set of control flows that include the respective vulnerability is determined. Further, for each relevant set of control flows, a flow-sensitive analysis of at least one of the control flows in the corresponding relevant set is performed by a hardware processor to assess the validity of the respective vulnerability.
Claims
exact text as granted — not AI-modified1 .- 25 . (canceled)
26 . A method for security analysis of an application comprising:
conducting a flow-insensitive analysis on the application to obtain a set of potential vulnerabilities in the application; for each of the potential vulnerabilities, determining a relevant set of control flows that include the respective vulnerability; and for each relevant set of control flows, performing, by a hardware processor, a flow-sensitive analysis of at least one of the control flows in the corresponding relevant set to assess a validity of the respective vulnerability.
27 . The method of claim 26 , wherein the performing the flow-sensitive analysis further comprises performing the flow sensitive analysis on a concatenation of control flows in at least one of the relevant sets.
28 . The method of claim 27 , wherein a plurality of the control flows in the concatenation denote multiple executions of the application.
29 . The method of claim 28 , wherein the multiple executions denote separate interactions with a user.
30 . The method of claim 29 , wherein the application is a parallel program web application.
31 . The method of claim 26 , wherein the determining the relevant set of control flows that include the respective vulnerability further comprises determining a set of control flows that enable source to sink data propagation.
32 . The method of claim 26 , further comprising:
for each of the vulnerabilities, determining whether the respective vulnerability is reproduced by the flow-sensitive analysis.
33 . The method of claim 32 , further comprising:
outputting a report denoting each of the respective vulnerabilities that are reproduced by the flow-sensitive analysis.
34 . A method for security analysis of a web application comprising:
conducting a flow-insensitive analysis on the application to obtain a set of potential witnesses of vulnerabilities in the application; for each of the potential witnesses, restricting a scope of analysis within program code of the application to a relevant set of control flows; and for at least one of the relevant sets of control flows, performing, by a hardware processor, a flow-sensitive analysis of a concatenation of the control flows in the corresponding relevant set to assess a validity of the respective witness across multiple executions of the web application.
35 . The method of claim 34 , wherein a plurality of the control flows in the concatenation denote the multiple executions of the web application.
36 . The method of claim 35 , wherein the multiple executions denote separate interactions with a user.
37 . The method of claim 34 , wherein the restricting the scope of analysis further comprises determining a set of control flows that enable source to sink data propagation.
38 . The method of claim 34 , further comprising:
for each of the witnesses, determining whether the respective witness is reproduced by the flow-sensitive analysis.
39 . The method of claim 38 , further comprising:
outputting a report denoting each of the respective witnesses that are reproduced by the flow-sensitive analysis.
40 . A method for security analysis of an application comprising:
conducting a flow-insensitive analysis on the application to obtain a set of potential vulnerabilities in the application; for at least one of the potential vulnerabilities, determining a relevant sequence of control flows that enable source to sink data propagation; and for at least one relevant sequence of control flows, performing, by a hardware processor, a flow-sensitive analysis of a concatenation of a plurality of control flows in the corresponding relevant sequence to assess a validity of the respective vulnerability.
41 . The method of claim 40 , wherein a plurality of the control flows in the concatenation denote multiple executions of the application.
42 . The method of claim 41 , wherein the multiple executions denote separate interactions with a user.
43 . The method of claim 42 , wherein the application is a parallel program web application.
44 . The method of claim 40 , further comprising:
for each of the vulnerabilities, determining whether the respective vulnerability is reproduced by the flow-sensitive analysis.
45 . The method of claim 44 , further comprising:
outputting a report denoting each of the respective vulnerabilities that are reproduced by the flow-sensitive analysis.Join the waitlist — get patent alerts
Track US2014157419A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.