Distributed web application firewall

H - Electricity – 04 – L

Patent

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

H04L 29/06 (2006.01)

Patent

CA 2644386

A method for protecting a Web application running on a first local Web Server from hacker attacks, said Web Server being connectable to at least one client, the method comprising the following steps: - providing a plurality of preset rules on said Server, which correspond to specific characteristics of HTTP requests; - receiving an HTTP request on said server from the client, said HTTP request comprising a plurality of characteristics; - analyzing said characteristcs of said received HTTP request in accordance with said rules provided on said server; - rejecting said HTTP request, if said rules identify said HTTP request as harmful request; - accepting said HTTP request, if said rules identify said HTTP request as trustable request; - classifying said HTTP request as doubtful request, if said rules identify said request neither as harmful request nor as trustable request; - evaluating the characteristics of said doubtful request; - generating a learned rule on basis of the evaluation.

La présente invention se rapporte à un procédé permettant de protéger une application Web exécutée sur un premier serveur Web local contre les attaques, ledit serveur Web pouvant être connecté à au moins un client. Le procédé selon l'invention comprend les étapes consistant : à fournir une pluralité de règles prédéfinies sur ledit serveur, qui correspondent à des caractéristiques spécifiques de requêtes HTTP; à recevoir une requête HTTP émanant du client sur ledit serveur, ladite requête HTTP comportant une pluralité de caractéristiques; à analyser lesdites caractéristiques de la requête HTTP reçue, en accord avec les règles fournies sur ledit serveur; à rejeter la requête HTTP si les règles l'identifient comme étant une requête malveillante; à accepter la requête HTTP si les règles l'identifient comme étant une requête fiable; à classer la requête HTTP parmi les requêtes incertaines si les règles l'identifient comme n'étant ni une requête malveillante ni une requête fiable; à évaluer les caractéristiques de la requête incertaine; à générer une règle acquise sur la base de ladite évaluation.

LandOfFree

Say what you really think

Search LandOfFree.com for Canadian inventors and patents. Rate them and share your experience with other people.

Rating

Distributed web application firewall does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Distributed web application firewall, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Distributed web application firewall will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFCA-PAI-O-1568097

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.