IP Library › Granted Patent US 10,356,112
Granted Patent B2
US 10,356,112 · App. 15/066,843 · Granted Jul 16, 2019

Method of mitigating cookie-injection and cookie-replaying attacks

Inventor: Tao Wan (Ottawa, CA)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L63/1425H04L63/0272H04L63/1441H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,356,112
App. No.
15/066,843
Filed
Mar 10, 2016
Granted
Jul 16, 2019
Kind
B2
Art Unit
2495
USPC
726/15
Abstract

The present disclosure is drawn to systems, methods, and computer-readable media for mitigating cookie-injection and cookie-replaying attacks using a VPN client. The VPN client receives a session request regarding access to a private intranet. In response to the request, the VPN client retrieves cookie deleting criteria, and deletes all cookies which satisfy the cookie deleting criteria. Once all cookies satisfying the cookie deleting criteria are deleted, the VPN client proceeds with the session request.

Claims (37)

1. A computer-implemented method, comprising:

receiving, by a virtual private network (VPN) client application running on a computing device, a VPN communication session initialization request, the VPN client application is a browser plugin that receives the VPN communication session initialization request;

in response to receiving, by the VPN client application running on the computing device, the VPN communication session initialization request and prior to initiating a VPN communication session, deleting, by the VPN client application running on the computing device, cookies stored on the computing device which have attributes which satisfy cookie attributes specified in a session initialization cookie deleting criteria prior to closing of a web browser associated with the browser plugin; and

processing, by the VPN client application running on the computing device, the VPN communication session initialization request to initiate the VPN communication session after deleting the cookies which have attributes which satisfy cookie attributes specified in the session initialization cookie deleting criteria, the browser plugin instructing the web browser to establish the VPN communication session.

2. The method of claim 1 , further comprising retrieving, by the VPN client application running on the computing device, the session initialization cookie deleting criteria in response to receiving the VPN communication session initialization request.

3. The method of claim 1 , further comprising:

receiving, by the VPN client application running on the computing device, a VPN communication session termination request;

deleting, by the VPN client application running on the computing device, all cookies which have attributes which satisfy cookie attributes specified in a session termination cookie deleting criteria; and

processing, by the VPN client application running on the computing device, the VPN communication session termination request to terminate the VPN communication session.

4. The method of claim 3 , further comprising retrieving, by the VPN client application running on the computing device, the session termination cookie deleting criteria in response to receiving the VPN communication session termination request.

5. The method of claim 3 , wherein the session initialization cookie deleting criteria and the session termination cookie deleting criteria are the same.

6. The method of claim 1 , further comprising:

receiving, by the VPN client application running on the computing device, a timeout message for the VPN communication session;

deleting, by the VPN client application running on the computing device, all cookies which satisfy a session termination cookie deleting criteria; and

terminating, by the VPN client application running on the computing device, the VPN communication session.

7. The method of claim 6 , further comprising retrieving, by the VPN client application running on the computing device, the session termination cookie deleting criteria in response to receiving the timeout message.

8. The method of claim 1 , wherein the cookie attributes specified in the session initialization cookie deleting criteria comprises at least one cookie domain, wherein deleting cookies having attributes which satisfy the cookie attributes specified in the session initialization cookie deleting criteria comprises deleting cookies having a domain which matches any of the at least one cookie domain.

9. The method of claim 1 , wherein the session initialization cookie deleting criteria is retrieved over a network.

10. A system, comprising:

a processing unit; and

a memory, communicatively coupled to the processing unit and comprising computer-readable program instructions executable by the processing unit for:

receiving, by a virtual private network (VPN) client application running on the system, a VPN communication session initialization request, the VPN client application is a browser plugin that receives the VPN communication session initialization request;

in response to receiving, by the VPN client application running on the system, the VPN communication session initialization request and prior to initiating a VPN communication session, deleting, by the VPN client application running on the system, cookies stored on the system which have attributes which satisfy cookie attributes specified in a session initialization cookie deleting criteria prior to closing of a web browser associated with the browser plugin; and

processing, by the VPN client application running on the system, the VPN communication session initialization request to initiate the VPN communication session after deleting the cookies which have attributes which satisfy cookie attributes specified in the session initialization cookie deleting criteria, the browser plugin instructing the web browser to establish the VPN communication session.

11. The system of claim 10 , wherein the program instructions are further executable by the processing unit for retrieving, by the VPN client application running on the system, the session initialization cookie deleting criteria in response to receiving the VPN communication session initialization request.

12. The system of claim 10 , wherein the program instructions are further executable by the processing unit for:

receiving, by the VPN client application running on the system, a VPN communication session termination request;

deleting, by the VPN client application running on the system, all cookies which satisfy a session termination cookie deleting criteria; and

processing, by the VPN client application running on the system, the VPN communication session termination request to terminate the VPN communication session.

13. The system of claim 12 , wherein the program instructions are further executable by the processing unit for retrieving, by the VPN client application running on the system, the session termination cookie deleting criteria in response to receiving the VPN communication session termination request.

14. The system of claim 12 , wherein the session initialization cookie deleting criteria and the session termination cookie deleting criteria are the same.

15. The system of claim 10 , wherein the program instructions are further executable by the processing unit for:

receiving, by the VPN client application running on the system, a timeout message for the VPN communication session;

deleting, by the VPN client application running on the system, all cookies which satisfy a session termination cookie deleting criteria; and

terminating, by the VPN application client running on the system, the VPN communication session.

16. The system of claim 15 , wherein the program instructions are further executable by the processing unit for retrieving, by the VPN client application running on the system, the session termination cookie deleting criteria in response to receiving the timeout message.

17. The system of claim 10 , wherein the session initialization cookie deleting criteria is retrieved over a network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2016
From: WAN, TAO
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 037951/0761 →
Continuity (1)
Related Publication 20170264624A1 · Sep 14, 2017
Cited By (1)
US 12,238,101