×

Cross-domain access prevention

  • US 8,495,719 B2
  • Filed: 10/02/2008
  • Issued: 07/23/2013
  • Est. Priority Date: 10/02/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • accessing, via a processor, web-enabled content in a first domain including automatically executing a script in the content to receive request access to a web page in a second domain, the script being embedded in the web-enabled content;

    detecting, via the processor, the request from the first domain to access the second domain;

    applying, via the processor, cross-domain access heuristics to determine whether to allow the request, the cross-domain access heuristics defining determining common ownership characteristics between the first domain and the second domain;

    executing, via the processor, a client domain resolver for determining an associated Internet Protocol (IP) address or subnet for the second domain and storing the associated IP address or subnet in at least one cache, the executing of the client domain resolver in response to failing to determine the common ownership characteristics between the first and second domains;

    performing, via the processor, the requested access in response to determining that the request complies with at least one of the cross-domain access heuristics; and

    blocking, via the processor, the requested access in response to determining that the request fails to comply with the cross-domain access heuristics; and

    deleting, via the processor, the stored IP address or subnet in the at least one cache in response to the performing of the requested access or the blocking of the requested access.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×