Invention Grant
US08495135B2 Preventing cross-site request forgery attacks on a server 有权
防止服务器上的跨站点请求伪造攻击

Preventing cross-site request forgery attacks on a server
Abstract:
Preventing Cross-Site Request Forgery (CSRF) security attacks on a server in a client-server environment comprises: embedding a nonce and a script in all responses from the server to the client, the script adapted for executing to add the nonce to each request from the client to the server; sending the response with the nonce and the script to the client; and verifying that each request from the client includes the nonce. The script preferably modifies all objects, including dynamically generated objects, in a server response that may generate future requests to the server to add the nonce to the requests. The server verifies the nonce value in a request and optionally confirms the request with the client if the value is not the same as the value previously sent by the server. Server-side aspects might be embodied in the server or a proxy between the server and the client.
Public/Granted literature
Information query
Patent Agency Ranking
0/0