IP Library Granted Patent US 8,181,246
Granted Patent B2
US 8,181,246 · App. 12/143,168 · Granted May 15, 2012

System and method for preventing web frauds committed using client-scripting attacks

Assignee: Imperva, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,181,246
App. No.
12/143,168
Granted
May 15, 2012
Kind
B2
Abstract

A method for detecting and blocking Javascript hijacking attacks, comprising checking if an incoming request belongs to a valid session established between a client and a trusted server. When said incoming request does belong to a valid session, it is checked if a Referer header of said incoming request includes a valid domain name. The incoming request is marked as suspicious, when said incoming request does not include a valid domain name. It is checked if a respective response of said suspicious incoming request includes a script code. A preventive action responsive to a user input is taken when said respective response includes a script code.

Claims (22)

1. A method for detecting and blocking Javascript hijacking attacks, comprising:

checking, by a secure gateway connected to at least a trusted server and communicatively coupled to a client, if an incoming request does not belong to a valid session established between a client and a trusted server and transferring the incoming request to the trusted server in response to the incoming request not belonging to the valid session thereby completing the method; otherwise,

when said incoming request does belong to the valid session, checking if a Referer header field of said incoming request includes a domain name that is of a protected web-site hosted by the trusted server;

marking said incoming request as suspicious, when said incoming request does not include the domain name;

transferring the suspicious incoming request to the trusted server;

checking if a respective response of said suspicious incoming request includes a script code; and

taking a preventive action responsive to a user input when said respective response includes the script code by skipping processing of the respective response based on the user input, such that a hijacking attack to gain access to sensitive information conveyed to the client is prevented.

2. The method of claim 1 , wherein said preventive action is selected from a group consisting of: generating an alert, blocking said incoming request and blocking said respective response.

3. The method of claim 1 , wherein said user input is sought for by one of: displaying a request for user authorization and displaying an alert in a pop-up window.

4. The method of claim 2 , wherein generating the alert further comprises:

inserting a special purpose script code in a response sent to the client, wherein the special purpose script code allows a user to block the response from being executed over the client.

5. A non-transitory computer-readable medium having stored thereon computer executable code for detecting and blocking Javascript hijacking attacks, the computer executable code comprising:

checking, by a secure gateway connected to at least a trusted server and communicatively coupled to a client, if an incoming request does not belong to a valid session established between a client and a trusted server and transferring the incoming request to the trusted server in response to the incoming request not belonging to the valid session thereby completing the method; otherwise,

when said incoming request does belong to the valid session, checking if a Referer header field of said incoming request includes a domain name that is of a protected web-site hosted by the trusted server;

marking said incoming request as suspicious, when said incoming request does not include the domain name;

transferring the suspicious incoming request to the trusted server;

checking if a respective response of said suspicious incoming request includes a script code; and

taking preventive action responsive to a user input when said respective response includes the script code by skipping processing of the respective response based on the user input, such that a hijacking attack to gain access to sensitive information conveyed to the client is prevented.

6. The computer executable code of claim 5 , wherein said preventive action is selected from a group consisting of: generating an alert, blocking said incoming request and blocking said respective response.

7. The computer executable code of claim 5 , wherein said user input is sought for by one of: displaying a request for user authorization and displaying an alert in a pop-up window.

8. The computer executable code of claim 6 , wherein generating said alert further comprises:

inserting a special purpose script code in a response sent to said client, wherein said special purpose script code allows a user to block said respective response from being executed over said client.

Assignments (5)
RELEASE OF FIRST LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 048077/0672 Recorded Dec 1, 2023
From: BANK OF AMERICA, N.A., AS AGENT
To: IMPERVA, INC.
Reel/Frame 065743/0832 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 049676/0451 Recorded Dec 1, 2023
From: GOLDMAN SACH BANK USA, AS AGENT
To: IMPERVA, INC.
Reel/Frame 065743/0905 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 15, 2019
From: IMPERVA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 049676/0451 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 15, 2019
From: IMPERVA, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 048077/0672 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2008
From: SHULMAN, AMICHAI; KARLEBACH, GUY
To: IMPERVA, INC.
Reel/Frame 021302/0299 →
Continuity (2)
Provisional Application 60945123 · Jun 20, 2007
Related Publication 20080320567A1 · Dec 25, 2008