Automated Web Security Testing via Script Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web applications are vulnerable to security attacks such as cookie stealing and SQL attacks, making security testing difficult and time-consuming, and requiring continuous tracking of new vulnerabilities.

Innovation Solution

A method for security testing web applications that identifies potential vulnerabilities, generates security test scripts, and executes them to analyze and mitigate risks, using tools like Functional Test Script Generators and Security Test Script Generators to simulate user interactions and evaluate vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual security testing is performed, then security vulnerabilities can be identified, but the process is difficult and time-consuming

Engineering Contradiction:
Improvesecurity vulnerability identificationVSAvoidtesting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service security testing by automatically generating and executing test scripts against the web application without requiring manual intervention. The functional test script generator creates test cases that automatically probe for security vulnerabilities, allowing the system to test itself and eliminating the need for manual security auditing.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical security testing processes with automated computer-based systems. The functional test script generator and security test script generator automatically perform what would otherwise require manual analysis, substituting human expertise with automated algorithms that can systematically evaluate security vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If extensive domain-specific knowledge is required for security testing, then accurate vulnerability detection is achieved, but the complexity and difficulty of testing increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidtesting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system provides universal security testing capabilities through automated generators that can assess multiple types of vulnerabilities (SQL injection, cookie stealing, script attacks) using a single integrated platform. The functional test script generator and security test script generator work together to provide comprehensive coverage without requiring separate specialized tools for each vulnerability type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces intermediary automated generators that bridge the gap between simple web applications and complex security analysis. The functional test script generator creates intermediate test representations that the security test script generator then translates into actual vulnerability assessment tests, simplifying the overall process while maintaining accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If new security vulnerabilities are continuously tracked, then current security threats are addressed, but the need for continuous learning and updating increases

Engineering Contradiction:
Improvecurrent security threat responseVSAvoidcontinuous tracking time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security assessment actions by automatically generating and executing comprehensive vulnerability tests before actual attacks occur. The functional test script generator creates test cases in advance that can detect emerging vulnerabilities, allowing proactive identification and remediation rather than reactive response to security threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the security test script generator analyzes test results and provides feedback on vulnerability status. This continuous feedback loop enables the system to automatically update its understanding of security threats and adapt to new vulnerability patterns without requiring manual reconfiguration.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7975296B2Automated security threat testing of web pages
Publication Date: 2011.07.05 ORACLE INT CORP
  • US7975296B2 patent drawing
  • US7975296B2 patent drawing
  • US7975296B2 patent drawing

AI summary

A method of security testing a web application is presented. The method identifies a web application to be tested, determines potential security vulnerabilities of the web application, generates one or more security tests for testing the potential vulnerabilities, and executes the security test on the web application. The results of the security testing are then used to make the web application less vulnerable to security attacks.