Invention Grant
- Patent Title: Methods and systems for scripting defense
- Patent Title (中): 防御脚本的方法和系统
-
Application No.: US12558173Application Date: 2009-09-11
-
Publication No.: US08931084B1Publication Date: 2015-01-06
- Inventor: Cem Paya , Johann Tomas Sigurdsson , Sumit Gwalani
- Applicant: Cem Paya , Johann Tomas Sigurdsson , Sumit Gwalani
- Applicant Address: US CA Mountain View
- Assignee: Google Inc.
- Current Assignee: Google Inc.
- Current Assignee Address: US CA Mountain View
- Agency: Fox Rothschild LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08 ; G06F21/12

Abstract:
Methods and systems for cross-site scripting (XSS) defense are described herein. An embodiment includes, embedding one or more tags in content at a server to identify executable and non-executable regions in the content and transmitting the content with the tags to a client based on a request from the client. Another embodiment includes receiving content embedded with one or more permission tags from a server, processing the content and the permission tags, and granting permission to a browser to execute executable content in the content based on the permission tags. A method embodiment also includes receiving content embedded with one or more verify tags from a server, performing an integrity check using the verify tags and granting permission to a browser to execute executable content in the content based on the integrity check.
Information query