发明名称 CLIENT SIDE PROTECTION AGAINST DRIVE-BY PHARMING VIA REFERRER CHECKING
摘要 <p>HTTP requests initiated from a web browser of a client computer system are proxied prior to release to a router (204), such as a home router. HTTP requests identifying a referrer URL (208) corresponding to routable, public IP address and a target URL (206) corresponding to a non-routable, private IP address are determined to be indicative of a drive-by pharming attack (210), and are blocked from sending to the router (240). HTTP requests not identifying a referrer URL corresponding to a routable, public IP address and a target URL corresponding to a non-routable, private IP address, the HTTP request are not determined to be indicative of a drive-by pharming attack, and are released for sending to the router (218). In some embodiments, an HTTP response received in response to a released HTTP request is proxied prior to release to the web browser. An HTTP response having content of type text/html or script (410) is modified as indicated to prevent malicious activity and released to the web browser.</p>
申请公布号 EP1990977(B1) 申请公布日期 2012.10.03
申请号 EP20080155808 申请日期 2008.05.07
申请人 SYMANTEC CORPORATION 发明人 COOLEY, SHAUN;TROLLOPE, ROWAN
分类号 H04L29/06;G06F21/00;H04L29/08 主分类号 H04L29/06
代理机构 代理人
主权项
地址