发明名称 Method for detecting and applying different security policies to active client requests running within secure user web sessions
摘要 A method for detecting and applying security policy to active client requests within a secure user session begins by applying a first heuristic to a plurality of requests for a particular resource to identify a pattern indicating of an active client. In one embodiment, the heuristic evaluates a frequency of requests for the particular resource across one or more secure user sessions. Later, upon receipt of a new request for the particular resource, a determination is then made whether the new request is consistent with the pattern. If so, an action is taken with respect to a secure session policy. In one embodiment, the action bypasses the secure session policy, which policy is associated with an inactivity time-out that might otherwise have been triggered upon receipt of the new request. In addition, a second heuristic may be applied to determine whether a response proposed to be returned (in response to the new request) is expected by the active client. If so, the response is returned unaltered. If, however, applying the second heuristic indicates that the response proposed to be returned is not expected by the active client, the response is modified to create a modified response, which is then returned.
申请公布号 US2012284767(A1) 申请公布日期 2012.11.08
申请号 US201113101458 申请日期 2011.05.05
申请人 HOCKINGS CHRISTOPHER JOHN;NORVILL TREVOR SCOTT;EXTON SCOTT ANTHONY;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 HOCKINGS CHRISTOPHER JOHN;NORVILL TREVOR SCOTT;EXTON SCOTT ANTHONY
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址