IP Library Granted Patent US 8,640,216
Granted Patent B2
US 8,640,216 · App. 12/645,924 · Granted Jan 28, 2014

Systems and methods for cross site forgery protection

Inventors: Craig Anderson (Sunnyvale, CA); Anoop Reddy (San Jose, CA); Yariv Keinan (San Francisco, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,640,216
App. No.
12/645,924
Filed
Dec 23, 2009
Granted
Jan 28, 2014
Kind
B2
Art Unit
2439
USPC
726/11
Abstract

The present solution described herein is directed towards systems and methods to prevent cross-site request forgeries based on web form verification using unique identifiers. The present solution tags each form from a server that is served out in the response with a unique and unpredictable identifier. When the form is posted, the present solution enforces that the identifier being returned is the same as the one that was served out to the user. This prevents malicious unauthorized third party users from submitting a form on a user's behalf since they cannot guess the value of this unique identifier that was inserted.

Claims (30)

1. A method of protecting against forgery of forms, the method comprising:

(a) identifying, by an application firewall executing on an intermediary device deployed between a plurality of clients and one or more servers, that a response to a first request of a client comprising: application layer forms of a first form and a second form, the first form corresponds to a policy that identifies forms within network traffic traversing the intermediary device in which to include at least one form identifier;

(b) generating, by an identifier generator of the application firewall responsive to the identification, a form identifier for the first form that is unique and unpredictable among form identifiers transmitted via the intermediary device, the identifier generator using a random number from a random number generator as a seed for generating the form identifier;

(c) transmitting, by the application firewall to the client, the response comprising the form identifier embedded in the first form;

(d) receiving, by the application firewall, a second request from the client to send form data for the first form to the server;

(e) identifying, by the application firewall, that the second request from the client includes form data corresponding to the first form previously transmitted by the application firewall; and

(f) determining, by the application firewall responsive to identifying that the second request includes the form data, whether to send the second request to the server based on whether the second request identifies the form identifier transmitted with the response.

2. The method of claim 1 , wherein step (b) further comprises generating at least one form identifier for each of the first form and the second form, each of the at least one form identifier unique and unpredictable among form identifiers embedded in the response transmitted by the intermediary device.

3. The method of claim 1 , wherein step (c) further comprises embedding, by the application firewall, the form identifier into a hidden field in the first form.

4. The method of claim 1 , wherein step (c) further comprises embedding, by the application firewall, the form identifier into an attribute value of the first form.

5. The method of claim 1 , wherein step (d) further comprises receiving, by the application firewall, the second request comprising a POST request of the first form to the server.

6. The method of claim 1 , wherein step (d) further comprises receiving, by the application firewall, the second request comprising a GET request with form data for the first form.

7. The method of claim 1 , wherein step (f) further comprises determining, by the application firewall, that the second request does not have any form identifier and responsive to this determination, not sending the second request to the server.

8. The method of claim 1 , wherein step (f) further comprises determining, by the application firewall, that the second request's form identifier does not match the form identifier of the response and responsive to this determination, not sending the second request to the server.

9. The method of claim 1 , wherein step (f) further comprises determining, by the application firewall, that the second request's form identifier does match the form identifier of the response and responsive to this determination, sending the second request to the server.

10. The method of claim 1 , further comprising receiving, by the application firewall, a third request from one of the client or a second client, the third request sending form data for a form for which the application firewall has not generated the form identifier and not sending the third request to the server.

11. A system for protecting against forgery of forms comprising:

an application firewall executing on an intermediary device deployed between a plurality of clients and one or more servers comprising:

a form verification engine of an application firewall executing on the intermediary device identifying that a response to a first request of a client comprising: application layer forms of a first form and second form the first form corresponds to a policy that identifies forms within network traffic traversing the intermediary device in which to include at least one form identifier;

an identifier generator of the application firewall generating a form identifier for the first form that is unique and unpredictable among form identifiers transmitted via the intermediary device, the identifier generator using a random number from a random number generator as a seed for generating the form identifier;

wherein the form verification engine transmits to the client the response comprising the form identifier embedded in the first form, receives a second request from the client to send form data for the first form to the server, identifies that the second request from the client includes form data corresponding to the first form previously transmitted by the application firewall and determines whether to send the second request to the server based on whether the second request identifies the form identifier transmitted with the response responsive to identifying that the second request includes the form data.

12. The system of claim 11 , wherein the identifier generator generates at least one form identifier for each of the first form and the second form, each of the at least one form identifier unique and unpredictable among form identifiers embedded in the response transmitted by the intermediary device.

13. The system of claim 11 , wherein the form verification engine embeds the form identifier into a hidden field in the first form.

14. The system of claim 11 , wherein the form verification engine embeds the form identifier into an attribute value of the first form.

15. The system of claim 11 , wherein the form verification engine receives the second request comprising a POST request of the first form to the server.

16. The system of claim 11 , wherein the form verification engine receives the second request comprising a GET request with form data for the first form.

17. The system of claim 11 , wherein the form verification engine determines that the second request does not have any form identifier and responsive to this determination, does not send the second request to the server.

18. The system of claim 11 , wherein the form verification engine determines that the second request's form identifier does not match the form identifier of the response and responsive to this determination, does not send the second request to the server.

19. The system of claim 11 , wherein the form verification engine determines that the second request's form identifier matches the form identifier of the response and responsive to this determination, sends the second request to the server.

20. The system of claim 11 , wherein the form verification engine receives a third request from one of the client or a second client, the third request sending form data for a form for which the identifier generator has not generated the form identifier and not sending the third request to the server.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2010
From: ANDERSON, CRAIG; REDDY, ANOOP; KEINAN, YARIV
To: CITRIX SYSTEMS, INC.
Reel/Frame 024048/0383 →
Continuity (1)
Related Publication 20110154473A1 · Jun 23, 2011