Invention Grant
US08176539B2 Methods for protecting against cookie-poisoning attacks in networked-communication applications
有权
在网络通信应用中防止cookie中毒攻击的方法
- Patent Title: Methods for protecting against cookie-poisoning attacks in networked-communication applications
- Patent Title (中): 在网络通信应用中防止cookie中毒攻击的方法
-
Application No.: US12259305Application Date: 2008-10-28
-
Publication No.: US08176539B2Publication Date: 2012-05-08
- Inventor: Ori Aldor , Neta Solomon
- Applicant: Ori Aldor , Neta Solomon
- Applicant Address: IL Tel Aviv
- Assignee: Check Point Software Technologies Ltd.
- Current Assignee: Check Point Software Technologies Ltd.
- Current Assignee Address: IL Tel Aviv
- Agent Mark M. Friedman
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
The present invention discloses methods, media, and gateways for protecting against cookie-poisoning attacks in networked-communication applications. Methods include the steps of: creating a protected gateway cookie, generated by a gateway, for a server cookie, generated by a server, wherein the server cookie is received by the gateway in an HTTP response message; and validating, by the gateway, that a client cookie from a client request has a corresponding gateway cookie with expected field values. Preferably, the field values include at least one field value selected from the group consisting of: a name, a hash value computed over the server cookie, a hash-function index, a timestamp, a nonce, a hash value computed over newly-generated values, a path, a domain, an expiration, and an HTTP-only value. Preferably, the gateway cookie is signed with a secret key. Most preferably, the secret key is generated by a secret seed.
Public/Granted literature
- US20100107234A1 METHODS FOR PROTECTING AGAINST COOKIE-POISONING ATTACKS IN NETWORKED-COMMUNICATION APPLICATIONS Public/Granted day:2010-04-29
Information query