发明名称 A METHOD AND SYSTEM FOR PREVENTING CROSS-SITE REQUEST FORGERY ATTACKS ON A SERVER
摘要 A method and system for preventing Cross-Site Request Forgery (CSRF) security attacks on a server in a client-server environment. The method includes embedding a nonce and a script to all responses from the server to the client wherein when executed the script will add the nonce to each request from the client to the server; sending the response with the nonce and the script to the client; and verifying that each said request from the client includes the nonce sent by the server from the server to the client. The script modifies all objects, including dynamically generated objects, in a server response that may generate future requests to the server to add the nonce to the requests. The server verifies the nonce value in a request and confirms the request with the client if the value is not the same as the value previously sent by the server. Server-side aspects of the invention might be embodied in the server or a proxy between the server and the client.
申请公布号 CA2694326(A1) 申请公布日期 2010.05.18
申请号 CA20102694326 申请日期 2010.03.10
申请人 IBM CANADA LIMITED - IBM CANADA LIMITEE 发明人 PODJARNY, GUY;AMIT, YAIR;SHARABANI, ADI
分类号 H04L9/32;G06F21/00;G06Q20/40 主分类号 H04L9/32
代理机构 代理人
主权项
地址