Unlock instant, AI-driven research and patent intelligence for your innovation.

A network information processing method, firewall device, and system

An information processing method and network technology, which are applied in the fields of systems, network information processing methods and firewall devices, can solve the problems of indeterminate matching rules, false negatives, and unsatisfactory XSS protection, and achieve convenient maintenance and reduced harm. Effect

Active Publication Date: 2018-01-09
MICRO DREAM TECHTRONIC NETWORK TECH CHINACO
View PDF8 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0018] Although the Web Application Firewall is so powerful, it still has some disadvantages
First, the matching rules are difficult to determine. If there are too few, there will be false positives, and if there are too many, it will affect the performance of the server. Second, the deployment is troublesome. Once the rules are modified, the server needs to be restarted, which is not convenient for maintenance. In terms of XSS protection, only It can protect against reflective XSS, but it can't do anything about stored XSS
And because the web application firewall is based on character features, the protection accuracy is not high
[0019] It can be seen from the above that the existing technology is not satisfactory in terms of protection against XSS, so how to set up new protection devices and protection methods has become a problem that technicians need to consider

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A network information processing method, firewall device, and system
  • A network information processing method, firewall device, and system
  • A network information processing method, firewall device, and system

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0041] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.

[0042] The main idea of ​​the present invention is to protect XSS through client browser script, which is different from the previous firewall device based on server configuration.

[0043] Such as figure 2 Shown is a flowchart of a network information processing method according to an embodiment of the present invention, and the method includes:

[0044] 203. When the page that needs to be protected is loaded in the client browser, the ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The embodiment of the invention provides a network information processing method and a firewall device and system. The method includes the steps that when a page needing to be protected is loaded by a client browser, a client browser script starts a protection script in the page; the protection script captures page information of the page; the captured page information is compared with preset protection rules through the protection script, and if the captured page information accords with the protection rules, corresponding processing is executed. The page information comprises a static module and a dynamic module. The capture of the page information by the protection script involves capture of the static module by installing an inline event and / or capture of the dynamic module by rewriting a native application programming interface (API). Injection scripts can be observed by flexibly using the client browser script and are intercepted or pre-warned, safety staff can conveniently find the problem as soon as possible, and harm to a user is reduced.

Description

Technical field [0001] The present invention relates to the field of network communication technology, in particular to a network information processing method, firewall device and system. Background technique [0002] Cross Site Scripting (CSS is also called XSS, cross-site scripting attack), refers to the attacker inserting malicious script code into the Web (WorldWide Web, World Wide Web) page, when the user enables the browser to visit the page, the malicious script code will be Execute and attack users. In order to prevent cross-site scripting attacks on the pages accessed by the user's browser, Content Security Policy (CSP) appears. CSP is mainly used to define which resources can be loaded on the page. CSP aims to reduce a kind of content injection, such as XSS cross-site scripting. CSP is a public security policy statement defined by the developer. Simply put, the rules governed by CSP can specify trusted source content, such as scripts, pictures, iframes (inline frame el...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06
CPCH04L63/0227H04L63/1416
Inventor 谢作孟罗诗尧
Owner MICRO DREAM TECHTRONIC NETWORK TECH CHINACO