Patents by Inventor Bill Pennington

Bill Pennington has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8893282
    Abstract: An improved method and apparatus for client-side application analysis is provided. Client-side application analysis involves determining and testing, using client-side application interfaces and the like, data input points and analyzing client requests and server responses. A security vulnerability analyzer can be employed to analyze content for client-side application files, such as Flash files and Java applets, extract addresses and data parameters embedded in the client-side application file, and modify the data parameters according to user-defined test criteria. The modified data parameters are transmitted as part of a request to a respective server used to service requests from the client-side application files. The security vulnerability analyzer analyzes the response from the server to ascertain if there are any security vulnerabilities associated with the interface between the client-side application file and the server.
    Type: Grant
    Filed: August 27, 2012
    Date of Patent: November 18, 2014
    Assignee: WhiteHat Security, Inc.
    Inventors: Bill Pennington, Jeremiah Grossman, Robert Stone, Siamak Pazirandeh
  • Publication number: 20130055403
    Abstract: An improved method and apparatus for client-side web application analysis is provided. Client-side web application analysis involves determining and testing, using client-side application interfaces and the like, data input points and analyzing client requests and server responses. In one embodiment, a security vulnerability analyzer is employed to analyze web page content for client-side application files, such as Flash files and Java applets, extract web addresses and data parameters embedded in the client-side application file, and modify the data parameters according to user-defined test criteria. The modified data parameters are transmitted as part of a request to a respective web server used to service the client-side application files. The security vulnerability analyzer analyzes the response from the server to ascertain if there are any security vulnerabilities associated with the interface between the client-side application file and the web server.
    Type: Application
    Filed: August 27, 2012
    Publication date: February 28, 2013
    Applicant: WhiteHat Security, Inc.
    Inventors: Bill Pennington, Jeremiah Grossman, Robert Stone, Siamak Pazirandeh
  • Patent number: 8281401
    Abstract: An improved method and apparatus for client-side web application analysis is provided. Client-side web application analysis involves determining and testing, using client-side application interfaces and the like, data input points and analyzing client requests and server responses. A security vulnerability analyzer can analyze web page content for client-side application files, such as Flash files and Java applets, extract web addresses and data parameters embedded in the client-side application file, and modify the data parameters according to user-defined test criteria. The modified data parameters are transmitted as part of a request to a respective web server used to service the client-side application files. The security vulnerability analyzer analyzes the response from the server to ascertain if there are any security vulnerabilities associated with the interface between the client-side application file and the web server.
    Type: Grant
    Filed: January 24, 2006
    Date of Patent: October 2, 2012
    Assignee: Whitehat Security, Inc.
    Inventors: Bill Pennington, Jeremiah Grossman, Robert Stone, Siamak Pazirandeh
  • Patent number: 7467402
    Abstract: A web application security scanner (WASS) includes a login manager configured to perform an automated login to a web site. The automated login may be performed when the login manager detects that a login session has ended. The login manager is configured to determine credentials for the web site to allow the WASS to access the web site. The WASS may then use the credentials to continue scanning the web site. Thus, previously unscannable web pages may be accessed in the web site because of the automated login process.
    Type: Grant
    Filed: August 23, 2005
    Date of Patent: December 16, 2008
    Assignee: Whitehat Security, Inc.
    Inventors: Bill Pennington, Jeremiah Grossman, Robert Stone, Siamak Pazirandeh
  • Publication number: 20060288220
    Abstract: A web application firewall (WAFs) used to secure websites from many known and unknown vulnerabilities is described. In one embodiment, the WAF is installed between a server that is serving web content and a network over which clients access the website hosted on the server. The WAF is configured to provide security from external attacks by preventing the website from receiving data that it did not send, and that the data received was not altered by a client. The WAF encodes outbound HTTP response data such that when a client or interloper follows one of the links or other constructs in the response data, the WAF can determine the validity of the next client request. In one embodiment, each universal resource locator link is encrypted and checked for validity when it is returned to the server via the WAF.
    Type: Application
    Filed: May 1, 2006
    Publication date: December 21, 2006
    Applicant: WhiteHat Security, Inc.
    Inventors: Bill Pennington, Jeremiah Grossman, Robert Stone, Siamak Pazirandeh, Lex Arquette
  • Publication number: 20060195588
    Abstract: An improved method and apparatus for client-side web application analysis is provided. Client-side web application analysis involves determining and testing, using client-side application interfaces and the like, data input points and analyzing client requests and server responses. In one embodiment, a security vulnerability analyzer is employed to analyze web page content for client-side application files, such as Flash files and Java applets, extract web addresses and data parameters embedded in the client-side application file, and modify the data parameters according to user-defined test criteria. The modified data parameters are transmitted as part of a request to a respective web server used to service the client-side application files. The security vulnerability analyzer analyzes the response from the server to ascertain if there are any security vulnerabilities associated with the interface between the client-side application file and the web server.
    Type: Application
    Filed: January 24, 2006
    Publication date: August 31, 2006
    Applicant: WhiteHat Security, Inc.
    Inventors: Bill Pennington, Jeremiah Grossman, Robert Stone, Siamak Pazirandeh