Invention Grant
- Patent Title: Client-side prevention of cross-site request forgeries
- Patent Title (中): 客户端防止跨站点请求伪造
-
Application No.: US12627864Application Date: 2009-11-30
-
Publication No.: US08904521B2Publication Date: 2014-12-02
- Inventor: James Paul Schneider
- Applicant: James Paul Schneider
- Applicant Address: US NC Raleigh
- Assignee: Red Hat, Inc.
- Current Assignee: Red Hat, Inc.
- Current Assignee Address: US NC Raleigh
- Agency: Lowenstein Sandler LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08

Abstract:
Cross-site request forgeries (“XSRF”) can be prevented using a client-side plugin on a client computer. The client computer accesses a content provided by a third party host via a network and generates a request to a web application as directed by the content. The client-side plugin determines whether the request is associated with suspicious activities based on the content, a source of the request and a list of approved hosts associated with the target host. In response to a determination that the request is associated with suspicious activities, the plugin removes authentication credentials from the request and sends the request to the web application.
Public/Granted literature
- US20110131635A1 CLIENT-SIDE PREVENTION OF CROSS-SITE REQUEST FORGERIES Public/Granted day:2011-06-02
Information query