首页> 外国专利> Hostname validation and policy evasion prevention

Hostname validation and policy evasion prevention

机译:主机名验证和政策逃避预防

摘要

A request to establish a session with a first server is received from a client device. The first server is associated with a first hostname, and the request includes information identifying a second hostname purported to correspond to the first server. A Domain Name System (DNS) lookup using the second hostname is performed. A determination that the second hostname was spoofed by the client device is determined based on a response to the DNS lookup. In response to the determination being made that the request received from the client device includes the spoofed second hostname, a determination that the client device has injected or overridden at least one of an HTTP Host header and a Server Name Indicator in the request is made, and an action to take with respect to the client device is determined.
机译:从客户端设备接收与第一服务器建立会话的请求。第一服务器与第一个主机名相关联,并且请求包括标识声称对应于第一服务器的第二主机名的信息。执行使用第二个主机名的域名系统(DNS)查找。基于对DNS查找的响应确定客户端设备欺骗第二主机名的确定。响应于确定从客户端设备接收的请求包括欺骗的第二主机名,确定客户端设备已经注入或覆盖了该请求中的至少一个HTTP主机头和服务器名称指示符,确定关于客户端设备的动作。

著录项

  • 公开/公告号US10965716B2

    专利类型

  • 公开/公告日2021-03-30

    原文格式PDF

  • 申请/专利权人 PALO ALTO NETWORKS INC.;

    申请/专利号US201916669256

  • 申请日2019-10-30

  • 分类号G06F17;H04L29/06;H04L29/12;H04L29/08;G06F16/2453;

  • 国家 US

  • 入库时间 2022-08-24 17:57:52

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号