Web server and method for preventing cross-site scripting attack

A cross-site scripting attack and server technology, which is applied in the field of web servers to prevent cross-site scripting attacks, can solve the problems of difficult server-side XSS attacks, high maintenance costs, and failure to eliminate XSS attacks from the root cause, so as to avoid executing malicious code. , high configurability, eliminating the effect of cross-site scripting attacks

A cross-site scripting attack and server technology, which is applied in the field of web servers to prevent cross-site scripting attacks, can solve the problems of difficult server-side XSS attacks, high maintenance costs, and failure to eliminate XSS attacks from the root cause, so as to avoid executing malicious code. , high configurability, eliminating the effect of cross-site scripting attacks

CN104348789AActive Publication Date: 2015-02-11CHINA UNIONPAY

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Web server and method for preventing cross-site scripting attack
  • Web server and method for preventing cross-site scripting attack

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0027] figure 1 is a schematic structural diagram of a Web server for preventing cross-site scripting attacks according to an embodiment of the present invention. Such as figure 1 As shown, the web server for preventing cross-site scripting attacks disclosed by the present invention includes a preprocessing unit 1 , a filter 2 and a web resource processing unit 3 . Wherein, the preprocessing unit 1 intercepts the HTTP request after receiving the HTTP request from the browser, and determines whether to perform a filtering operation for the HTTP request according to the filter mapping table, and if it is determined that it needs to perform a filtering operation for the HTTP request. HTTP request filtering operation, then the HTTP request is passed to the filter. After the filter 2 receives the HTTP request, it performs a filtering operation for the HTTP request according to predetermined cross-site scripting attack judgment rules and cross-site scripting attack processing rule...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention proposes a web server and a method for preventing cross-site scripting attack, wherein the method includes: after the Web server receives an HTTP request from a browser, intercepting the HTTP request, and determining, according to a filter mapping table, whether a filtering operation with respect to the HTTP request is to be executed; if it is determined that the filtering operation with respect to the HTTP request is needed to be executed, executing, by the Web server, the filtering operation with respect to the intercepted HTTP request according to a predetermined cross-site scripting attack judging rule and a cross-site scripting attack processing rule. The Web server and the method for preventing cross-site scripting attack disclosed in the invention can prevent effectively the cross-site scripting attack with respect to the browser and / or Web server.

Description

technical field [0001] The present invention relates to a Web server and a method, more specifically, to a Web server and a method for preventing cross-site scripting attacks. Background technique [0002] At present, with the increasingly wide application of computers and networks and the increasing variety of business types in different fields, secure data transmission between browsers and Web servers is required to prevent cross-site scripting attacks (that is, XSS, which refers to HTTP response due to The browser contains illegal data, which causes the browser to execute malicious code, thereby obtaining the user's cookie data (which is the data stored on the user's local terminal in order to identify the user's identity and track the session), and then create fraudulent pages to implement phishing attacks, etc. etc.) are becoming more and more important. [0003] The two existing ways to prevent cross-site scripting attacks are as follows: (1) Divide the web page into ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
11 Feb 2015
Publication
CN104348789A
IPC
H04L29/06
CPC
H04L63/145; H04L67/02
Inventors
杨曦; 周继恩