发明名称 CROSS-SITE SCRIPTING ATTACK PROTECTION
摘要 A technique to provide runtime output sanitization filtering of web application content that contains multiple contexts in which dynamic output is included. To facilitate this operation, dynamically-generated content is prepared for sanitization in advance, preferably by being "marked" by the web application itself (or by middleware used by or associated with the application). Preferably, given dynamically-generated content is marked by enclosing it between dynamic content indicators. Then, after the document generation is completed but before it is output (delivered), the application-generated content is processed by a content sanitization filter. The filter uses the dynamic content identifiers to identify and locate the content that needs output escaping. The filter detects the appropriate context within which the dynamically-generated content has been placed, and it then applies the appropriate escaping. In this manner, the output content is fully prepared for escaping in advance even if it is being assembled from multiple input sources that do not operate in the same runtime environment. In this approach, escaping is added after all other application processing is finished and the complete document is ready for delivery to the requesting end user.
申请公布号 WO2012010394(A1) 申请公布日期 2012.01.26
申请号 WO2011EP61061 申请日期 2011.06.30
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION;ZURKO, MARY, ELLEN;PIECZUL, OLGIERD, STANISLAW;MCGLOIN, MARK 发明人 ZURKO, MARY, ELLEN;PIECZUL, OLGIERD, STANISLAW;MCGLOIN, MARK
分类号 H04L29/06;H04L29/08 主分类号 H04L29/06
代理机构 代理人
主权项
地址