发明名称 ENCODING LABELS IN VALUES TO CAPTURE INFORMATION FLOWS
摘要 <p>Methods, servers, and systems for encoding security labels in a dynamic language value to allow cross script communications within client application while limiting the types of information that is allowed to be communicated back to a host server. Static analysis is performed during compilation, and the results are used to generate and insert additional code that updates, modifies and propagates labels (e.g., JavaScript labels) attached to values (e.g., JavaScript values) during execution of a program. To support popular language features that allow for strong integration with other web-based systems, malicious code is allowed to perform operations locally (e.g., on the client), and a detection and prevention mechanism identifies and stops malicious code from sending requests or gathered information over the network, naturalizing attacks and improving the security of applications that embed dynamic language code.</p>
申请公布号 EP2776970(A1) 申请公布日期 2014.09.17
申请号 EP20120798035 申请日期 2012.09.28
申请人 QUALCOMM INCORPORATED 发明人 KERSCHBAUMER, CHRISTOPH;RESHADI, MOHAMMAD H.
分类号 G06F21/52;G06F21/53;G06F21/62 主分类号 G06F21/52
代理机构 代理人
主权项
地址