发明授权
US07051368B1 Methods and systems for screening input strings intended for use by web servers
有权
用于筛选要由Web服务器使用的输入字符串的方法和系统
- 专利标题: Methods and systems for screening input strings intended for use by web servers
- 专利标题(中): 用于筛选要由Web服务器使用的输入字符串的方法和系统
-
申请号: US09437584申请日: 1999-11-09
-
公开(公告)号: US07051368B1公开(公告)日: 2006-05-23
- 发明人: Michael Howard , Vikas Malhotra
- 申请人: Michael Howard , Vikas Malhotra
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 代理机构: Lee & Hayes, PLLC
- 主分类号: G06F12/14
- IPC分类号: G06F12/14
摘要:
Methods and systems of screening input strings that are intended for use by a Web server are described. In the described embodiment, an attack pattern is determined that can be used to attack a Web server. A search pattern is defined that can be used to detect the attack pattern. The search pattern is defined in a flexible, extensible manner that permits variability among its constituent parts. An input string that is intended for use by a Web server is received and evaluated using the search pattern to ascertain whether the attack pattern is present. If an attack pattern is found that matches the search pattern, then a remedial action is implemented.
信息查询