首页> 外国专利> Persistent cross-site scripting vulnerability detection

Persistent cross-site scripting vulnerability detection

机译:持久跨站点脚本漏洞检测

摘要

Various techniques for detecting a persistent cross-site scripting vulnerability are described herein. In one example, a method includes detecting, via the processor, a read operation executed on a resource using an instrumentation mechanism and returning, via the processor, a malicious script in response to the read operation. The method also includes detecting, via the processor, a write operation executed on the resource using the instrumentation mechanism and detecting, via the processor, a script operation executed by the malicious script that results in resource data being sent to an external computing device from a client device. Furthermore, the method includes receiving, via the processor, metadata indicating the execution of the read operation, the write operation, and the script operation.
机译:本文描述了用于检测持久跨站点缺陷漏洞的各种技术。在一个示例中,一种方法包括经由处理器检测在资源上使用仪器机制执行的读取操作,并经由处理器响应于读取操作返回恶意脚本。该方法还包括经由处理器检测在资源上使用仪器机制执行的写入操作,并经由处理器检测由恶意脚本执行的脚本操作,这些脚本可以导致资源数据从a中发送到外部计算设备客户端设备。此外,该方法包括通过处理器接收指示读取操作的执行,写入操作和脚本操作的元数据。

著录项

  • 公开/公告号US11005877B2

    专利类型

  • 公开/公告日2021-05-11

    原文格式PDF

  • 申请/专利权人 HCL TECHNOLOGIES LIMITED;

    申请/专利号US201916353795

  • 发明设计人 EMANUEL BRONSHTEIN;ROEE HAY;SAGI KEDMI;

    申请日2019-03-14

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-24 18:37:37

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号