Invention Grant
- Patent Title: Guarding against cross-site request forgery (CSRF) attacks
-
Application No.: US14947129Application Date: 2015-11-20
-
Publication No.: US10454949B2Publication Date: 2019-10-22
- Inventor: Lewis Lo , Ching-Yun Chao , Li Yi , Leonardo A. Uzcategui , John Yow-Chun Chang , Rohan Gandhi
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Michael O'Keefe; Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L9/00
- IPC: H04L9/00 ; H04L29/06

Abstract:
Cross-Site Request Forgery attacks are mitigated by a CSRF mechanism executing at a computing entity. The CSRF mechanism is operative to analyze information associated with an HTTP request for a resource. The HTTP request typically originates as an HTTP redirect from another computing entity, such as an enterprise Web portal. Depending on the nature of the information associated with the HTTP request, the HTTP request may be rejected because the CSRF mechanism determines that the request is or is likely associated with a CSRF attack. To facilitate this determination, the approach leverages a new type of “referer” attribute, a trustedReferer, which indicates that the request originates from a server that has previously established a trust relationship with the site at which the CSRF mechanism executes. The trustedReferer attribute typically is set by the redirecting entity, and in an HTTP request header field dedicated for that attribute.
Public/Granted literature
- US20170149803A1 Guarding against cross-site request forgery (CSRF) attacks Public/Granted day:2017-05-25
Information query