Invention Grant
- Patent Title: Detecting stolen authentication cookie attacks
- Patent Title (中): 检测被盗认证cookie攻击
-
Application No.: US11592920Application Date: 2006-11-02
-
Publication No.: US08079076B2Publication Date: 2011-12-13
- Inventor: Tarun Soin , Vineet Dixit , Yixin Sun
- Applicant: Tarun Soin , Vineet Dixit , Yixin Sun
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Hickman Palermo Truong & Becker LLP
- Main IPC: H04L29/00
- IPC: H04L29/00

Abstract:
In one embodiment, an apparatus comprises logic for detecting stolen authentication cookie attacks. A first transport connection is established between a client and a gateway server, where the first transport connection is authenticated by the gateway server. A first authentication cookie is associated with a client session, between the client and the gateway server, that includes the first transport connection. A second transport connection is established at the gateway server. A request is received over the second transport connection. The request includes the first authentication cookie to associate the second transport connection with the client session. A second authentication cookie is generated for the client session and is returned over the second transport connection. Thereafter, a determination is made whether the second authentication cookie is received over the first transport connection. An attack is detected when the second authentication cookie is not received over the first transport connection.
Public/Granted literature
- US20080127323A1 Detecting stolen authentication cookie attacks Public/Granted day:2008-05-29
Information query