首页> 外国专利> Method and Apparatus for Serving Content Elements of a Markup Language Document Protected Against Cross-Site Scripting Attack

Method and Apparatus for Serving Content Elements of a Markup Language Document Protected Against Cross-Site Scripting Attack

机译:服务于跨站点脚本攻击的标记语言文档的内容元素的方法和设备

摘要

A web application decomposed into one or more domain sandboxes ensures that the contents of each sandbox are protected from attacks on the web application outside that sandbox. Sandboxing is achieved on a per-element basis by identifying content that should be put under protection, generating a secure domain name for the identified content, and replacing the identified content with a unique reference (e.g., an iframe) to the generated secure domain. The identified content is then served only from the generated secure domain using a content handler.
机译:分解为一个或多个域沙箱的Web应用程序可确保保护每个沙箱的内容免受对该沙箱外部的Web应用程序的攻击。通过标识应受到保护的内容,为标识的内容生成安全域名并使用对生成的安全域的唯一引用(例如,iframe)替换标识的内容,可以在每个元素的基础上实现沙盒。然后,仅使用内容处理程序从生成的安全域中提供已标识的内容。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号