The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 22, 2019

Filed:

Nov. 20, 2015
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Lewis Lo, Toronto, CA;

Ching-Yun Chao, Austin, TX (US);

Li Yi, Beijing, CN;

Leonardo A. Uzcategui, Georgetown, TX (US);

John Yow-Chun Chang, Austin, TX (US);

Rohan Gandhi, Austin, TX (US);

Attorneys:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 9/00 (2006.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); H04L 63/123 (2013.01); H04L 63/1466 (2013.01); H04L 63/1483 (2013.01);
Abstract

Cross-Site Request Forgery attacks are mitigated by a CSRF mechanism executing at a computing entity. The CSRF mechanism is operative to analyze information associated with an HTTP request for a resource. The HTTP request typically originates as an HTTP redirect from another computing entity, such as an enterprise Web portal. Depending on the nature of the information associated with the HTTP request, the HTTP request may be rejected because the CSRF mechanism determines that the request is or is likely associated with a CSRF attack. To facilitate this determination, the approach leverages a new type of 'referer' attribute, a trustedReferer, which indicates that the request originates from a server that has previously established a trust relationship with the site at which the CSRF mechanism executes. The trustedReferer attribute typically is set by the redirecting entity, and in an HTTP request header field dedicated for that attribute.


Find Patent Forward Citations

Loading…