首页> 外国专利> Protecting documents from cross-site scripting attacks

Protecting documents from cross-site scripting attacks

机译:保护文档免受跨站点脚本攻击

摘要

In various implementations, an embedded document receives untrusted content from a containing document, where the embedded document is in the containing document. In some cases, the untrusted content is received by the containing document from a server and is forwarded to the embedded document without rendering the untrusted content in the containing document. Instead, the untrusted content is rendered in the embedded document. A sandbox policy is enforced on the embedded document such that the rendered untrusted content is restricted from accessing data associated with the containing document. The untrusted content may comprise malicious code that when rendered executes an XXS attack that attempts to access the data associated with the containing document. However, because the untrusted content is rendered in the embedded document, the malicious code may be denied access to the data, thereby preventing the XSS attack from succeeding.
机译:在各种实现中,嵌入式文档从包含的文档接收不受信任的内容,其中嵌入式文档位于包含文档中。在某些情况下,由包含的文档从服务器接收不受信任的内容,并将转发到嵌入式文档,而无需呈现包含文档中的不受传记的内容。相反,不受信任的内容在嵌入式文档中呈现。在嵌入式文档上强制强制执行Sandbox策略,以便呈现不可信的内容被限制访问与包含文档相关联的数据。不受信任的内容可以包括恶意代码,当呈现执行尝试访问与包含文档相关联的数据的XXS攻击时的恶意代码。然而,由于不受信任的内容在嵌入式文档中呈现,所以可以拒绝恶意代码对数据进行访问,从而防止XSS攻击成功。

著录项

  • 公开/公告号US11063956B2

    专利类型

  • 公开/公告日2021-07-13

    原文格式PDF

  • 申请/专利权人 ADOBE INC.;

    申请/专利号US201414541785

  • 发明设计人 DAMIEN ANTIPA;ANTONIO SANSO;

    申请日2014-11-14

  • 分类号H04L29/06;G06F21/53;

  • 国家 US

  • 入库时间 2022-08-24 19:53:53

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号