IP Library › Granted Patent US 10,789,360
Granted Patent B2
US 10,789,360 · App. 15/880,398 · Granted Sep 29, 2020

Protection against third party JavaScript vulnerabilities

Inventor: Martin Johns (Karlsruhe, DE)
Assignee: SAP SE
G06F21/563G06F16/93G06F21/51G06F21/54G06F21/568H04L63/101G06F16/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,789,360
App. No.
15/880,398
Granted
Sep 29, 2020
Kind
B2
Abstract

Embodiments protect against security vulnerabilities arising from 3 rd party JavaScript code. A browser receives from a server, a document including a first JavaScript. The browser in turn references a list stored in a database to recognize the first JavaScript as originating from other than the server. This recognition process may involve obtaining a stacktrace. The browser then references a second JavaScript in order to instrument a document object model (DOM) feature (e.g., global API, DOM element-attached API, DOM node property) to sanitize the first JavaScript. For instrumenting a global API, this may comprise overwriting a global reference in the first JavaScript with a replacement reference to a sanitization function. For instrumenting the DOM element-attached API or the DOM node property, the instrumenting may comprise altering a prototype of the DOM node element. The browser causes the DOM feature to sanitize the first JavaScript, and passes a sanitized JavaScript for execution.

Claims (48)

1. A computer-implemented method comprising:

a browser receiving from a server, a document including a first JavaScript;

the browser referencing a list stored in a database to recognize the first JavaScript as originating from other than the server;

the browser referencing a second JavaScript for instrumenting a document object model (DOM) feature to sanitize the first JavaScript, said instrumenting comprises altering a prototype of the DOM node element;

the browser causing the DOM feature to sanitize the first JavaScript;

the browser temporarily restoring the prototype to its original state;

the browser assigning an original functionality to the DOM element node;

the browser reinstrumenting the DOM feature to sanitize the first JavaScript; and

the browser passing a sanitized JavaScript to the document for execution.

2. A method as in claim 1 wherein the DOM feature comprises an application program interface (API).

3. A method as in claim 2 wherein the API comprises a global API, and the instrumenting comprises:

before calling an original functionality of the first JavaScript, overwriting a global reference in the first JavaScript with a replacement reference to a sanitization function.

4. A method as in claim 3 further comprising the browser adding another reference to the global API.

5. A method as in claim 2 wherein the API comprises a local API attached to a DOM node element.

6. A method as in claim 1 wherein the DOM feature comprises a property of a DOM node element.

7. A method as in claim 6 further comprising the browser adding properties to the prototype.

8. A method as in claim 1 further comprising the browser obtaining a stacktrace to recognize the first JavaScript as originating from other than the server.

9. A method as in claim 1 wherein the list comprises a whitelist.

10. A non-transitory computer readable storage medium embodying a computer program for performing a method, said method comprising:

a browser receiving from a server, a document including a first JavaScript;

the browser referencing a list stored in a database to recognize the first JavaScript as originating from other than the server by obtaining a stacktrace;

the browser referencing a second JavaScript for instrumenting a document object model (DOM) feature to sanitize the first JavaScript, said instrumenting comprises altering a prototype of the DOM node element;

the browser causing the DOM feature to sanitize the first JavaScript;

the browser temporarily restoring the prototype to its original state;

the browser assigning an original functionality to the DOM element node;

the browser reinstrumenting the DOM feature to sanitize the first JavaScript; and

the browser passing a sanitized JavaScript to the document for execution.

11. A non-transitory computer readable storage medium as in claim 10 wherein the DOM feature comprises an application program interface (API).

12. A non-transitory computer readable storage medium as in claim 11 wherein the API comprises a global API, and the instrumenting comprises:

before calling an original functionality of the first JavaScript, overwriting a global reference in the first JavaScript with a replacement reference to a sanitization function.

13. A non-transitory computer readable storage medium as in claim 11 wherein the API comprises a local API attached to a DOM node element.

14. A non-transitory computer readable storage medium as in claim 11 wherein the DOM feature comprises a property of a DOM node element.

15. A computer system comprising:

one or more processors;

a software program, executable on said computer system, the software program configured to cause an in-memory database engine to cause:

a browser to receive from a server, a document including a first JavaScript;

the browser to reference a list stored in an in-memory database to recognize the first JavaScript as originating from other than the server;

the browser to reference a second JavaScript for instrumenting a document object model (DOM) feature to sanitize the first JavaScript, said instrumenting comprises altering a prototype of the DOM node element;

the browser to cause the DOM feature to sanitize the first JavaScript;

the browser temporarily restoring the prototype to its original state;

the browser assigning an original functionality to the DOM element node;

the browser reinstrumenting the DOM feature to sanitize the first JavaScript; and

the browser to pass a sanitized JavaScript to the document for execution.

16. A computer system as in claim 15 wherein in response to the browser receiving the second JavaScript, the software program is further configured to cause the in-memory database engine to store the second JavaScript in the in-memory database.

17. A computer system as in claim 15 wherein the DOM feature comprises a global API, and the instrumenting comprises:

before calling an original functionality of the first JavaScript, overwriting a global reference in the first JavaScript with a replacement reference to a sanitization function.

18. A computer system as in claim 15 wherein the DOM feature comprises a local API attached to a DOM node element.

19. A computer system as in claim 15 wherein the DOM feature comprises a property of a DOM node element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2018
From: JOHNS, MARTIN
To: SAP SE
Reel/Frame 044733/0741 →
Continuity (1)
Related Publication 20190228150A1 · Jul 25, 2019
Cited By (3)
US 12,267,352 US 12,475,254 US 12,669,982