Patent · US Active

System and method for preventing web frauds committed using client-scripting attacks

US9455997B2 · kind B2 · utility

8Cited by
3References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 15, 2012
Grant dateSep 27, 2016
Priority date
Expiry dateApr 12, 2033

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/0236
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method for detecting and blocking Javascript hijacking attacks, comprising checking if an incoming request belongs to a valid session established between a client and a trusted server. When said incoming request does belong to a valid session, it is checked if a Referer header of said incoming request includes a valid domain name. The incoming request is marked as suspicious, when said incoming request does not include a valid domain name. It is checked if a respective response of said suspicious incoming request includes a script code. A preventive action responsive to a user input is taken when said respective response includes a script code.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.