首页> 外国专利> Cross-site scripting attack protection

Cross-site scripting attack protection

机译:跨站点脚本攻击防护

摘要

A technique to provide runtime output sanitization filtering of web application content that contains multiple contexts in which dynamic output is included. To facilitate this operation, dynamically-generated content is prepared for sanitization in advance, preferably by being “marked” by the web application itself (or by middleware). Preferably, given dynamically-generated content is marked by enclosing it between dynamic content indicators. After the document generation is completed but before it is output, the application-generated content is processed by a content sanitization filter. The filter uses the dynamic content identifiers to identify and locate the content that needs output escaping. The filter detects the appropriate context within which the dynamically-generated content has been placed and applies escaping. The output content is prepared for escaping in advance even if assembled from multiple sources that do not operate in the same runtime environment.
机译:一种提供Web应用程序内容的运行时输出清理过滤的技术,该应用程序包含多个包含动态输出的上下文。为了促进此操作,最好预先准备好动态生成的内容以进行清理,最好是由Web应用程序本身(或由中间件)“标记”。优选地,给定的动态生成的内容通过将其封闭在动态内容指示符之间来进行标记。在文档生成完成之后但在输出之前,应用程序生成的内容由内容清理过滤器处理。筛选器使用动态内容标识符来标识和定位需要输出转义的内容。筛选器检测动态生成的内容已放置在其中的适当上下文,并应用转义。即使从不在同一运行时环境中运行的多个源进行汇编,输出内容也可以预先转义。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号