Abstract: Various embodiments of systems, methods, software tools, etc. for providing secure web application development are provided. One embodiment comprises a method for developing a secure web application. One such method comprises: analyzing code associated with a web application to identify at least one vulnerable input; and validating the at least one vulnerable input.
Abstract: An automated Web security analysis system and process identifies security vulnerabilities in a target Internet Web site by parsing through the target Web site to search for a predetermined list of common security vulnerabilities. The process is recursive, exploiting information gathered throughout the process to search for additional security vulnerabilities. A prioritized list of detected security vulnerabilities is then presented to a user, including preferably a list of recommendations to eliminate the detected security vulnerabilities.
Type:
Grant
Filed:
November 28, 2000
Date of Patent:
February 7, 2006
Assignee:
S.P.I. Dynamics Incorporated
Inventors:
Dennis Wayne Hurst, Darrin Ray Barrall, Caleb Ikaki Sima