发明名称 DEALING WITH WEB ATTACKS USING CRYPTOGRAPHICALLY SIGNED HTTP COOKIES
摘要 According to one embodiment, a security gateway (SG) is coupled between a hypertext transport protocol (HTTP) client and a web application server. Responsive to a first HTTP message being transmitted between the HTTP client and the web application server as part of an HTTP session, the SG generates security gateway session security state information (SGI) based on a policy. The SG also generates a digital signature (SGS) from the SGI, creates an SG signed session security state information cookie (SGC), and sends the SGC to the HTTP client for storage instead of storing the SGI in the SG. Responsive to a second HTTP message of the HTTP session, the SG attempts to validate a claim made in the second HTTP request using at least the policy and the SGC that is supposed to be returned with the second HTTP message.
申请公布号 US2013055384(A1) 申请公布日期 2013.02.28
申请号 US201113218421 申请日期 2011.08.25
申请人 SHULMAN AMICHAI;BE'ERY TAL ARIEH 发明人 SHULMAN AMICHAI;BE'ERY TAL ARIEH
分类号 G06F0021/000020 主分类号 G06F0021/000020
代理机构 代理人
主权项
地址