Invention Grant
US08176539B2 Methods for protecting against cookie-poisoning attacks in networked-communication applications 有权
在网络通信应用中防止cookie中毒攻击的方法

Methods for protecting against cookie-poisoning attacks in networked-communication applications
Abstract:
The present invention discloses methods, media, and gateways for protecting against cookie-poisoning attacks in networked-communication applications. Methods include the steps of: creating a protected gateway cookie, generated by a gateway, for a server cookie, generated by a server, wherein the server cookie is received by the gateway in an HTTP response message; and validating, by the gateway, that a client cookie from a client request has a corresponding gateway cookie with expected field values. Preferably, the field values include at least one field value selected from the group consisting of: a name, a hash value computed over the server cookie, a hash-function index, a timestamp, a nonce, a hash value computed over newly-generated values, a path, a domain, an expiration, and an HTTP-only value. Preferably, the gateway cookie is signed with a secret key. Most preferably, the secret key is generated by a secret seed.
Information query
Patent Agency Ranking
0/0