Unlock instant, AI-driven research and patent intelligence for your innovation.

A browser-based information processing method and device

An information processing method and technology for an information processing device, which are applied in the field of communication, can solve the problems of insufficient XSS protection and low security, and achieve the effects of improving security and improving protection.

Active Publication Date: 2019-09-17
TENCENT TECH (SHENZHEN) CO LTD
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0005] The purpose of the present invention is to provide a browser-based information processing method and device, aiming to solve the technical problems of insufficient XSS protection and low security of browsers in the prior art

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A browser-based information processing method and device
  • A browser-based information processing method and device
  • A browser-based information processing method and device

Examples

Experimental program
Comparison scheme
Effect test

no. 1 example

[0038] See figure 2 , figure 2 It is a schematic flowchart of a browser-based information processing method provided by the first embodiment of the present invention.

[0039] In step S201, the content input by the user is received in the input box of the current website of the browser.

[0040] Wherein, the execution subject of the browser-based information processing method is a client, and the client may include a desktop computer, a tablet computer, a mobile phone with touch function, etc., which has a storage unit and is installed with a microprocessor and has computing capabilities. equipment.

[0041] In step S202, the content input by the user is parsed to generate content fragments.

[0042] That is to say, analyze and judge each part of the content input by the user.

[0043] In step S203, it is determined whether the content segment meets a preset format, and at the same time it is determined whether the current website meets a preset rule.

[0044] It is understandab...

no. 2 example

[0050] See image 3 , image 3 It is a schematic flowchart of a browser-based information processing method provided by the second embodiment of the present invention. The method steps include:

[0051] In step S301, the content input by the user is received in the input box of the current website of the browser.

[0052] Wherein, the execution subject of the browser-based information processing method is a client, and the client may include a desktop computer, a tablet computer, a mobile phone with touch function, etc., which has a storage unit and is installed with a microprocessor and has computing capabilities. equipment.

[0053] It is understandable that the content entered by the user can be in the following form:

[0054] http: / / victim / test.php? name= alert("XSS") .

[0055] In step S302, the content input by the user is analyzed to generate content fragments.

[0056] In step S303, the tag to which the content segment belongs is obtained, and the format information corres...

no. 3 example

[0071] See Figure 4 , Figure 4 It is a schematic flowchart of a browser-based information processing method provided by the third embodiment of the present invention. The method steps include:

[0072] In step S401, the content input by the user is received in the input box of the current website of the browser.

[0073] Wherein, the execution subject of the browser-based information processing method is a client, and the client may include a desktop computer, a tablet computer, a mobile phone with touch function, etc., which has a storage unit and is installed with a microprocessor and has computing capabilities. equipment.

[0074] It is understandable that the content entered by the user can be in the following form:

[0075] http: / / victim / test.php? name= alert("XSS") .

[0076] In step S402, the content input by the user is analyzed to generate content fragments.

[0077] In step S403, the tag to which the content segment belongs is obtained, and the format information corre...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a browser-based information processing method and device. The method comprises the following steps: receiving content input by a user in an input box of a current website of a browser; analyzing the content input by the user to generate content fragments; judging whether the content fragments meet preset formats, and meanwhile, judging whether the current website accords with preset rules; and if the content fragments meet the preset formats and the current website accords with the preset rules, sending the content fragments meeting the preset formats to a server. Through simultaneous limitation of the formats of the input content and the current website, accurate judgment can be made according to the current situation, thereby improving protection level of the browser against the XSS, and improving safety.

Description

Technical field [0001] The invention belongs to the field of communication technology, and in particular relates to a browser-based information processing method and device. Background technique [0002] Cross Site Scripting (XSS, Cross Site Script) is a common way to attack browsers on the current network. XSS is divided into stored XSS and rebound XSS. Rebound XSS uses website developers to verify the parameters of input scripts, so that malicious attackers can insert malicious hypertext markup language (html, Hypertext markup language) into Web pages. Text Markup language) code. When the user browses the page, the html code embedded in the Web will be executed, which will cause the leakage of user information or trick the user into entering malicious URLs, and achieve the purpose of malicious attacks. [0003] However, domestic browsers basically have no protective measures against such attacks. Most of them just use the built-in protection methods of IE or Google (chrome) bro...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L29/08
Inventor 毛睿
Owner TENCENT TECH (SHENZHEN) CO LTD