会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 4. 发明申请
    • In-line website securing system with HTML processor and link verification
    • 使用HTML处理器和链接验证的在线网站安全系统
    • US20060288220A1
    • 2006-12-21
    • US11415794
    • 2006-05-01
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak PazirandehLex Arquette
    • Bill PenningtonJeremiah GrossmanRobert StoneSiamak PazirandehLex Arquette
    • H04L9/00
    • H04L63/02
    • A web application firewall (WAFs) used to secure websites from many known and unknown vulnerabilities is described. In one embodiment, the WAF is installed between a server that is serving web content and a network over which clients access the website hosted on the server. The WAF is configured to provide security from external attacks by preventing the website from receiving data that it did not send, and that the data received was not altered by a client. The WAF encodes outbound HTTP response data such that when a client or interloper follows one of the links or other constructs in the response data, the WAF can determine the validity of the next client request. In one embodiment, each universal resource locator link is encrypted and checked for validity when it is returned to the server via the WAF.
    • 描述了用于从许多已知和未知的漏洞保护网站的Web应用程序防火墙(WAFs)。 在一个实施例中,WAF被安装在服务于web内容的服务器和客户端访问在服务器上托管的网站的网络之间。 WAF被配置为通过防止网站收到未发送的数据,并且接收到的数据未被客户端更改,从而提供外部攻击的安全性。 WAF编码出站HTTP响应数据,使得当客户端或内部访问者遵循响应数据中的一个链接或其他结构时,WAF可以确定下一个客户端请求的有效性。 在一个实施例中,当通过WAF返回到服务器时,每个通用资源定位符链​​路被加密并检查其有效性。