首页>
外国专利>
Method for detecting and applying different security policies to active client requests running within secure user web sessions
Method for detecting and applying different security policies to active client requests running within secure user web sessions
展开▼
机译:用于检测不同的安全策略并将其应用于安全用户Web会话中运行的活动客户端请求的方法
展开▼
页面导航
摘要
著录项
相似文献
摘要
A method for detecting and applying security policy to active client requests within a secure user session begins by applying a first heuristic to a plurality of requests for a particular resource to identify a pattern indicating of an active client. In one embodiment, the heuristic evaluates a frequency of requests for the particular resource across one or more secure user sessions. Later, upon receipt of a new request for the particular resource, a determination is then made whether the new request is consistent with the pattern. If so, an action is taken with respect to a secure session policy. In one embodiment, the action bypasses the secure session policy, which policy is associated with an inactivity time-out that might otherwise have been triggered upon receipt of the new request. In addition, a second heuristic may be applied to determine whether a response proposed to be returned (in response to the new request) is expected by the active client. If so, the response is returned unaltered. If, however, applying the second heuristic indicates that the response proposed to be returned is not expected by the active client, the response is modified to create a modified response, which is then returned.
展开▼