IP Library Patent Application 12296062
Patent Application
App. No. 12/296,062

METHOD FOR PROVIDING WEB APPLICATION SECURITY

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/296,062
Abstract

A method for an HTTP server to decide whether a remote client is victim of a phishing ttack, comprising: —receiving a first HTTP request from the remote client on said HTTP Server; —responding to said first HTTP request, wherein a token is added to the response submitted to said remote client; —receiving a second HTTP request on said HTTP server; —judging whether the second HTTP request includes said token; —judging whether the token originates from said remote client; —processing the HTTP request when said remote client has really issued the second HTTP request.

Claims (22)

1 . A method for an HTTP server to decide whether a remote client is victim of a phishing attack, comprising:

receiving a first HTTP request from the remote client on said HTTP Server;

responding to said first HTTP request, wherein a token is added to the response submitted to said remote client;

receiving a second HTTP request on said HTTP server;

judging whether the second HTTP request includes said token;

judging whether the token originates from said remote client;

processing the HTTP request when said remote client has really issued the second HTTP request.

2 . The method according to claim 1 , wherein said token is a digital signature.

3 . The method according to claim 2 , wherein said digital signature is a cryptographic hash.

4 . The method according to claim 3 , wherein said token is added to a referrer of said first HTTP request and it is judged, whether said HTTP request includes the referrer.

5 . The method according to claim 4 , wherein a HTML warning page is returned, if said token does not match the client.

6 . The method according to claim 1 , further comprising: allowing the real emitter of an HTTP requests to access a resource.

7 . The method according to claim 6 , wherein a HTTP Server access control is maintained by programming the client browser to store a token or a similar tag for use in later HTTP requests on the same server.

8 . Device for deciding whether a remote client is victim of a phishing attack, comprising a Web server and a module for implementing on said HTTP server and for carrying out the method according to claim 1 .

9 . A computer program comprising computer program code means for performing the method of claim 1 when said program is run on a computer.

10 . A computer program as claimed in claim 10 embodied on a computer readable medium.

11 . A method for an HTTP server to decide whether a remote client is victim of a phishing attack according to claim 1 , substantially as described herein with reference to the accompanying drawings.

12 . Device for deciding whether a remote client is victim of a phishing attack according to claim 8 , substantially as described herein with reference to the accompanying drawings.

13 . The method according to claim 1 , wherein said token is added to a referrer of said first HTTP request and it is judged, whether said HTTP request includes the referrer.

14 . The method according to claim 13 , wherein a HTML warning page is returned, if said token does not match the client.

15 . The method according to claim 1 , wherein a HTML warning page is returned, if said token does not match the client.

16 . The method according to claim 1 , wherein a HTTP Server access control is maintained by programming the client browser to store a token or a similar tag for use in later HTTP requests on the same server.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
CONFIRMATORY PATENT ASSIGNMENT Recorded Aug 22, 2012
From: ZEUS TECHNOLOGY GMBH
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 028826/0033 →
CHANGE OF NAME Recorded May 25, 2012
From: APTUS 651. GMBH
To: ZEUS TECHNOLOGY GMBH
Reel/Frame 028304/0206 →
CORRECT ASSIGNEE NAME ON PREVIOUSLY RECORDED COVER SHEET FOR "ASSET SALE AND TRANSFER AGREEMENT RELATING TO THE ASSETS OF ART OF DEFENCE GMBH" ON REEL 027995 AND FRAMES 0600-0610 Recorded May 15, 2012
From: ART OF DEFENCE GMBH
To: APTUS 651. GMBH (TO BE RENAMED ZEUS TECHNOLOGY GMBH)
Reel/Frame 028207/0409 →
ASSET SALE AND TRANSFER AGREEMENT RELATING TO THE ASSETS OF ART OF DEFENCE GMBH Recorded Mar 23, 2012
From: ART OF DEFENCE GMBH
To: APTUS 651. GMBH (TO BE RENAMED ZEUS TECHNOLOGY GMBH); ZEUS TECHNOLOGY LIMITED
Reel/Frame 027995/0600 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2009
From: MEISEL, ALEXANDER
To: ART OF DEFENCE GMBH
Reel/Frame 023081/0891 →