首页> 外国专利> Method for detecting and applying different security policies to active client requests running within secure user web sessions

Method for detecting and applying different security policies to active client requests running within secure user web sessions

机译:用于检测不同的安全策略并将其应用于安全用户Web会话中运行的活动客户端请求的方法

摘要

A method for detecting and applying security policy to active client requests within a secure user session begins by applying a first heuristic to a plurality of requests for a particular resource to identify a pattern indicating of an active client. In one embodiment, the heuristic evaluates a frequency of requests for the particular resource across one or more secure user sessions. Later, upon receipt of a new request for the particular resource, a determination is then made whether the new request is consistent with the pattern. If so, an action is taken with respect to a secure session policy. In one embodiment, the action bypasses the secure session policy, which policy is associated with an inactivity time-out that might otherwise have been triggered upon receipt of the new request. In addition, a second heuristic may be applied to determine whether a response proposed to be returned (in response to the new request) is expected by the active client. If so, the response is returned unaltered. If, however, applying the second heuristic indicates that the response proposed to be returned is not expected by the active client, the response is modified to create a modified response, which is then returned.
机译:一种用于在安全用户会话内检测安全策略并将其应用于活动客户端请求的方法,是通过将第一启发式方法应用于对特定资源的多个请求以识别表示活动客户端的模式而开始的。在一实施例中,试探法评估跨一个或多个安全用户会话的对特定资源的请求的频率。稍后,在接收到对特定资源的新请求时,然后确定新请求是否与模式一致。如果是这样,则针对安全会话策略采取措施。在一个实施例中,该动作绕过安全会话策略,该策略与不活动超时相关联,否则该超时可能已经在接收到新请求时触发。另外,可以应用第二启发式方法来确定活动客户端是否期望提议返回的响应(响应于新请求)。如果是这样,则返回的响应将保持不变。但是,如果应用第二种启发式方法表明活动客户端未预期提议返回的响应,则修改响应以创建修改后的响应,然后将其返回。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号