发明名称 SYSTEM AND METHOD FOR PREVENTING WEB FRAUDS COMMITTED USING CLIENT-SCRIPTING ATTACKS
摘要 A method for detecting and blocking Javascript hijacking attacks, comprising checking if an incoming request belongs to a valid session established between a client and a trusted server. When said incoming request does belong to a valid session, it is checked if a Referer header of said incoming request includes a valid domain name. The incoming request is marked as suspicious, when said incoming request does not include a valid domain name. It is checked if a respective response of said suspicious incoming request includes a script code. A preventive action responsive to a user input is taken when said respective response includes a script code.
申请公布号 US2012227106(A1) 申请公布日期 2012.09.06
申请号 US201213472391 申请日期 2012.05.15
申请人 SHULMAN AMICHAI;KARLEBACH GUY 发明人 SHULMAN AMICHAI;KARLEBACH GUY
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址