Methods and systems for providing context-based outbound processing application firewalls
First Claim
Patent Images
1. A method comprising:
- Receiving an outbound message from an application executing on a hardware computing device with an application-level firewall, the outbound response being in response to a request message received from outside a system including the application-level firewall, wherein the outbound message includes at least a trustworthiness indicator and marking information based on inbound processing at the application-level firewall for the one or more portions of the outbound message comprising at least untrusted code or comprising at least untrusted data, wherein the outbound message is to be transmitted to a remote electronic device;
analyzing the outbound message based on the trustworthiness indicator and/or marking information, and context information with the application-level firewall; and
performing an action on traffic to the application based on encoded user data and the context information with one of the application-level firewall and the application by forwarding without modification when the outbound message is to be considered safe and redirecting the outbound message to a designated safe URL when the outbound message is to be considered unsafe.
1 Assignment
0 Petitions
Accused Products
Abstract
Outbound processing with application firewalls. An outbound message is generated with an application. The outbound message includes at least a trustworthiness indicator and/or marking information for the one or more portions of the outbound message. The outbound message is received by an application firewall. The outbound message is analyzed based on the trustworthiness indicator and/or marking information, and context information. An action is performed on the outbound message based on the trustworthiness indicator and/or marking information, and the context information.
177 Citations
18 Claims
-
1. A method comprising:
-
Receiving an outbound message from an application executing on a hardware computing device with an application-level firewall, the outbound response being in response to a request message received from outside a system including the application-level firewall, wherein the outbound message includes at least a trustworthiness indicator and marking information based on inbound processing at the application-level firewall for the one or more portions of the outbound message comprising at least untrusted code or comprising at least untrusted data, wherein the outbound message is to be transmitted to a remote electronic device; analyzing the outbound message based on the trustworthiness indicator and/or marking information, and context information with the application-level firewall; and performing an action on traffic to the application based on encoded user data and the context information with one of the application-level firewall and the application by forwarding without modification when the outbound message is to be considered safe and redirecting the outbound message to a designated safe URL when the outbound message is to be considered unsafe. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, are configurable to cause the one or more processors to:
-
receive an outbound message from an application executing on a hardware computing device with an application-level firewall, the outbound response being in response to a request message received from outside a system including the application-level firewall, wherein the outbound message includes at least a trustworthiness indicator and marking information based on inbound processing at the application-level firewall for the one or more portions of the outbound message comprising at least untrusted code or comprising at least untrusted data, wherein the outbound message is to be transmitted to a remote electronic device; analyze the outbound message based on the trustworthiness indicator and/or marking information, and context information with the application-level firewall; and perform an action on traffic to the application based on encoded user data and the context information with one of the application-level firewall and the application by forwarding without modification when the outbound message is to be considered safe and redirecting the outbound message to a designated safe URL when the outbound message is to be considered unsafe. - View Dependent Claims (9, 10, 11, 12, 13)
-
-
14. A system comprising:
at least one hardware computing device executing an application-level firewall, the server system to provide a multitenant environment, wherein the multitenant environment includes data for multiple client entities, each identified by a tenant identifier (ID) having one or more users associated with the tenant ID, users of each of multiple client identities can only access data identified by a tenant ID associated with the respective client entity, and the multitenant environment is at least a hosted database provided by an entity separate from the client entities, and provides on-demand database service to the client entities, the server system further to receive an outbound message from an application executing on a hardware computing device with an application-level firewall, the outbound response being in response to a request message received from outside the multitenant environment, wherein the outbound message includes at least a trustworthiness indicator and marking information based on inbound processing at the application-level firewall for the one or more portions of the outbound message comprising at least untrusted code or comprising at least untrusted data, wherein the outbound message is to be transmitted to a remote electronic device, to analyze the outbound message based on the trustworthiness indicator and/or marking information, and context information with the application-level firewall, and to perform an action on traffic to the application based on encoded user data and the context information with one of the application-level firewall and the application by forwarding without modification when the outbound message is to be considered safe and redirecting the outbound message to a designated safe URL when the outbound message is to be considered unsafe. - View Dependent Claims (15, 16, 17, 18)
Specification