×

Systems and methods for cross site forgery protection

  • US 8,640,216 B2
  • Filed: 12/23/2009
  • Issued: 01/28/2014
  • Est. Priority Date: 12/23/2009
  • Status: Active Grant
First Claim
Patent Images

1. A method of protecting against forgery of forms, the method comprising:

  • (a) identifying, by an application firewall executing on an intermediary device deployed between a plurality of clients and one or more servers, that a response to a first request of a client comprising;

    application layer forms of a first form and a second form, the first form corresponds to a policy that identifies forms within network traffic traversing the intermediary device in which to include at least one form identifier;

    (b) generating, by an identifier generator of the application firewall responsive to the identification, a form identifier for the first form that is unique and unpredictable among form identifiers transmitted via the intermediary device, the identifier generator using a random number from a random number generator as a seed for generating the form identifier;

    (c) transmitting, by the application firewall to the client, the response comprising the form identifier embedded in the first form;

    (d) receiving, by the application firewall, a second request from the client to send form data for the first form to the server;

    (e) identifying, by the application firewall, that the second request from the client includes form data corresponding to the first form previously transmitted by the application firewall; and

    (f) determining, by the application firewall responsive to identifying that the second request includes the form data, whether to send the second request to the server based on whether the second request identifies the form identifier transmitted with the response.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×