Invention Grant
- Patent Title: Method and apparatus for context-aware output escaping using dynamic content marking
-
Application No.: US12841747Application Date: 2010-07-22
-
Publication No.: US10372899B2Publication Date: 2019-08-06
- Inventor: Olgierd Pieczul , Mark Alexander McGloin , Mary Ellen Zurko
- Applicant: Olgierd Pieczul , Mark Alexander McGloin , Mary Ellen Zurko
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent David B. Woycechowsky; Jeffrey S. LaBaw; David H. Judson
- Main IPC: G06F17/00
- IPC: G06F17/00 ; G06F21/50 ; G06F21/51 ; G06F21/54 ; G06F21/56

Abstract:
A technique to provide runtime output sanitization filtering of web application content that contains multiple contexts in which dynamic output is included. To facilitate this operation, dynamically-generated content is prepared for sanitization in advance, preferably by being “marked” by the web application itself (or by middleware). Preferably, given dynamically-generated content is marked by enclosing it between dynamic content indicators. After the document generation is completed but before it is output, the application-generated content is processed by a content sanitization filter. The filter uses the dynamic content identifiers to identify and locate the content that needs output escaping. The filter detects the appropriate context within which the dynamically-generated content has been placed and applies escaping. The output content is prepared for escaping in advance even if assembled from multiple sources that do not operate in the same runtime environment.
Public/Granted literature
- US20120023394A1 Method and apparatus for context-aware output escaping using dynamic content marking Public/Granted day:2012-01-26
Information query