Data processing: database and file management or data structures – Database and file access – Post processing of search results
Reexamination Certificate
2011-03-01
2011-03-01
Le, Debbie (Department: 2168)
Data processing: database and file management or data structures
Database and file access
Post processing of search results
C707S713000, C707S722000, C707S758000, C707S781000, C726S022000, C726S026000
Reexamination Certificate
active
07899817
ABSTRACT:
Embodiments herein prevent or mitigate attacks on inverse query engines by providing safe mode routines that allow for the acceptance of third party messages and/or query expressions, as well as prevent trusted sources from accidental attacks. The mitigations fall into two categories: compile-time and runtime. Compile-time mitigations prevent query expressions from being accepted and compiled that are susceptible to known attacks. For example, the complexity of query expressions may be limited to functions with linear runtimes; constant memory usage; or ones that do not create large strings. Further, language constructs for the criteria in the query expression may not allow for nested predicates complexities. Runtime mitigations, on the other hand, monitor the data size and processing lengths of messages against the various query expressions. If these runtime quotas are exceeded, an exception or other violation indication may be thrown (e.g., abort), deeming the evaluation as under attack.
REFERENCES:
patent: 5249262 (1993-09-01), Baule
patent: 5432930 (1995-07-01), Song
patent: 5781432 (1998-07-01), Keeler et al.
patent: 6105023 (2000-08-01), Callan
patent: 6847974 (2005-01-01), Wachtel
patent: 7017016 (2006-03-01), Chujo et al.
patent: 7031958 (2006-04-01), Santosuosso
patent: 7047242 (2006-05-01), Ponte
patent: 2002/0112061 (2002-08-01), Shih et al.
patent: 2003/0055814 (2003-03-01), Chen et al.
patent: 2003/0163285 (2003-08-01), Nakamura et al.
patent: 2004/0010752 (2004-01-01), Chan et al.
patent: 2004/0060007 (2004-03-01), Gottlob et al.
patent: 2004/0068487 (2004-04-01), Barton et al.
patent: 2004/0172599 (2004-09-01), Calahan
patent: 2004/0193586 (2004-09-01), Sashida et al.
patent: 2004/0261019 (2004-12-01), Imamura et al.
patent: 2005/0091196 (2005-04-01), Day et al.
patent: 2005/0097084 (2005-05-01), Balmin et al.
patent: 2005/0165754 (2005-07-01), Valliappan et al.
patent: 2005/0177570 (2005-08-01), Dutta et al.
patent: 2005/0187906 (2005-08-01), Madan et al.
patent: 2005/0193023 (2005-09-01), Ismail
patent: 2005/0203957 (2005-09-01), Wang et al.
patent: 2005/0228768 (2005-10-01), Thusoo et al.
patent: 2005/0257201 (2005-11-01), Rose et al.
patent: 2006/0005122 (2006-01-01), Lemoine
patent: 2006/0005148 (2006-01-01), Cheng et al.
patent: 2006/0020631 (2006-01-01), Cheong Wan et al.
patent: 2006/0031233 (2006-02-01), Liu et al.
patent: 2006/0150162 (2006-07-01), Mongkolsmai et al.
patent: 2006/0173841 (2006-08-01), Bill
patent: 2006/0294095 (2006-12-01), Berk et al.
Neeraj Bajaj, “Easy and Efficient XMLProcessing: Upgrade to JAXP 1.3,” Sun Microsystems, Inc., Oct. 11, 2005,available athttp://www.tarari.com/PDF/Tarari—RAX4—ProductBrief.pdf (PDF enclosed entitled “Article 1,” 13 pages).
“Random Acess SML—RAX 4 Content Processor,” Tarari,available athttp://www.ccd.uab.es/˜joaquin/papers/intellcomm05.pdf (PDF enclosed entitled “Article 2,” 2 pages).
Garcia, et al., “Decoupling Components of an Attack Prevention System Using Publish/Subscribe,” University of Barcelona,available athttp://java.sun.com/developer/technicalArticles/xml/jaxp1-3/ (PDF enclosed entitled “Article3,” 11 pages).
Diplan Pompiliu
Eppley Geary L.
Madan Umesh
Stern Aaron A.
Le Debbie
Microsoft Corporation
Tran Bao G
Workman Nydegger
LandOfFree
Safe mode for inverse query evaluations does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Safe mode for inverse query evaluations, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Safe mode for inverse query evaluations will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-2755185