Patent · US Active

System and method for preventing web frauds committed using client-scripting attacks

US8181246B2 · kind B2 · utility

31Cited by
0References
8Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 20, 2008
Grant dateMay 15, 2012
Priority date
Expiry dateSep 2, 2030

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/0236
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method for detecting and blocking Javascript hijacking attacks, comprising checking if an incoming request belongs to a valid session established between a client and a trusted server. When said incoming request does belong to a valid session, it is checked if a Referer header of said incoming request includes a valid domain name. The incoming request is marked as suspicious, when said incoming request does not include a valid domain name. It is checked if a respective response of said suspicious incoming request includes a script code. A preventive action responsive to a user input is taken when said respective response includes a script code.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.