Invention Grant
- Patent Title: Safe script templating to provide reliable protection against attacks
- Patent Title (中): 安全脚本模板,提供可靠的攻击防护
-
Application No.: US13928872Application Date: 2013-06-27
-
Publication No.: US09231975B2Publication Date: 2016-01-05
- Inventor: Martin Johns
- Applicant: Martin Johns
- Applicant Address: DE Walldorf
- Assignee: SAP SE
- Current Assignee: SAP SE
- Current Assignee Address: DE Walldorf
- Agency: Fish & Richardson P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/52

Abstract:
Methods, systems, and computer-readable storage media for inhibiting cross-site scripting (XSS) attacks, where actions include receiving a computer-readable document that provides a content security policy (CSP) for a website and an extension to the CSP, the CSP specifying allowed script checksums, each allowed script checksum being associated with a script that is allowed to be executed, the extension requiring comparison of script checksums before respective scripts can be executed, receiving script templates and a value list, calculating an expected script checksum for each script template to provide respective expected script checksums, comparing the expected script checksums to the allowed script checksums, and determining that at least one expected script checksum matches an allowed script checksum, and in response, executing a respective script that corresponds to the at least one expected script checksum.
Public/Granted literature
- US20150007251A1 SAFE SCRIPT TEMPLATING TO PROVIDE RELIABLE PROTECTION AGAINST ATTACKS Public/Granted day:2015-01-01
Information query