IL259201A

Using the same query language for static and dynamic application security testing tools

Abstract

This record has no abstract on file.

IL259201A, drawing sheet 1
Sheet 1 of 3

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

15 claims: 2 independent, 13 dependent

  1. 1
    CLAIMS. 1. A computer-implemented method for detecting security vulnerabilities, comprising the steps of:receiving, into a memory of a computer, source code of at least one computer program to be analyzed;preparing a first data flow graph from the source code of one or more of the at least one computer program, using a static testing tool;instrumenting one or more of the at least one computer program;executing the instrumented one or more of the at least one computer program;collecting runtime events during an execution of the instrumented one or more of the at least one computer program;preparing a second data flow graph from the collected runtime events;receiving queries in a query language;applying one or more of the received queries to the first data flow graph and one or more of the received queries to the second data flow graph;and presenting results of the applying of the received queries on a display in a manner reporting a security vulnerability in one or more of the at least one computer program.
  2. 9
    A data processing system for detecting security vulnerabilities in a computer program comprising:a processor;a memory accessible to the processor storing program instructions and data objects therein;and an I/O facility linked to the processor;wherein execution of the program instructions cause the processor to perform the steps of: accepting via the I/O facility queries in a query language;receiving via the I/O facility into the memory source code of at least one computer program to be analyzed;259,201/2 preparing a first data flow graph from the source code of one or more of the at least one computer program, using a static testing tool;instrumenting one or more of the at least one computer program;executing the instrumented one or more of the at least one computer program in the processor and collecting runtime events during the execution;preparing a second data flow graph from the collected runtime events;receiving queries in a query language;applying one or more of the received queries to the first data flow graph and one or more of the received queries to the second data flow graph;and presenting results of the applying of the received queries on a display in a manner reporting a security vulnerability in one or more of the at least one computer program.