×

Cross-site request forgery protection

  • US 8,839,424 B2
  • Filed: 11/15/2012
  • Issued: 09/16/2014
  • Est. Priority Date: 11/15/2012
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method, comprising:

  • receiving, from a server, a cross-site request forgery (CSRF) warning signal that is associated with a service provider and is arranged to notify consumers the service provider provides services that are to be protected against cross-site request forgery-related exploits, wherein the CSRF warning signal includes an indication of an address to which a request, which is arranged to be executed by the service provider, is to be sent by the consumer side;

    determining, in a consumer side, whether the request, which is generated during a secure session between a consumer of the consumer side and the server, is arranged to be executed by a service provider and comprises a cross-site request that is cross-sited with respect to a server website with which the secure session is established; and

    taking a protective action, in the consumer side, in response to the determined cross-site request and in response to the cross-site request forgery warning signal received from the service provider, wherein the protective action includes blocking a portion of the cross-site request from being transmitted from the consumer to the server.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×