发明名称 Systems and methods for determining vulnerability to session stealing
摘要 Systems and methods for determining vulnerability to session stealing are disclosed. An example method includes intercepting, at a first computing device, an intercepted packet sent from a client to a second computing device different than the first computing device, the intercepted packet including a first instruction in a first portion of the intercepted packet, determining, using a template, a second portion of the intercepted packet that is a value that is changed by a calculated amount each time that the client sends a packet, changing the value by the calculated amount to determine a next value for a next packet, replacing the second portion of the intercepted packet with the next value to generate a modified packet, replacing the first portion of the modified packet with a second instruction, and transmitting the modified packet to the second computing device.
申请公布号 US8756697(B2) 申请公布日期 2014.06.17
申请号 US201213436818 申请日期 2012.03.30
申请人 Trustwave Holdings, Inc. 发明人 Ocepek Steven R.;Henrique Wendel Guglielmetti
分类号 H04L29/06;G06F11/00;G06F12/14;G06F12/16;G08B23/00 主分类号 H04L29/06
代理机构 Hanley, Flight & Zimmerman, LLC 代理人 Hanley, Flight & Zimmerman, LLC
主权项 1. A method comprising: intercepting, at a first computing device, an packet sent from a client to a second computing device different than the first computing device, the packet including a first instruction in a first portion of the packet; determining, using a template, a second portion of the packet that is a value that is changed by a calculated amount each time that the client sends a packet; changing the value by the calculated amount to determine a next value for a next packet; replacing the second portion of the packet with the next value to generate a modified packet; replacing the first portion of the modified packet with a second instruction; and transmitting the modified packet to the second computing device.
地址 Chicago IL US