Information security – Access control or authentication – Network
Reexamination Certificate
2004-08-11
2008-12-30
Tran, Ellen (Department: 2134)
Information security
Access control or authentication
Network
C726S011000, C726S013000
Reexamination Certificate
active
07472413
ABSTRACT:
A method and system for improving the security and control of internet
etwork web application processes, such as web applications. The invention enables validation of requests from web clients before the request reaches a web application server. Incoming web client requests are compared to an application model that may include an allowed navigation path within an underlying web application. Requests inconsistent with the application model are blocked before reaching the application server. The invention may also verify that application state data sent to application servers has not been inappropriately modified. Furthermore, the invention enables application models to be automatically generated by employing, for example, a web crawler to probe target applications. Once a preliminary application model is generated it can be operated in a training mode. An administrator may tune the application model by adding a request that was incorrectly marked as non-compliant to the application model.
REFERENCES:
patent: 5930792 (1999-07-01), Polcyn
patent: 6098093 (2000-08-01), Bayeh et al.
patent: 6311278 (2001-10-01), Raanan et al.
patent: 7146422 (2006-12-01), Marlatt et al.
patent: 2002/0023090 (2002-02-01), McGeachie
patent: 2003/0126558 (2003-07-01), Griffin
patent: 2003/0229780 (2003-12-01), Reamer
patent: 2005/0050010 (2005-03-01), Van der Linden
Bilal Siddiqui, “Deploying Web services with WSDL: Part 1”, Nov. 2001.
Bilal Siddiqui, “Deploying Web services with WSDL, Part 2: Simple Object Access Protocol (SOAP)”, Mar. 2002.
Darby & Darby PC
F5 Networks, Inc.
Poltorak Peter
Tran Ellen
Wiegand Jamie L.
LandOfFree
Security for WAP servers does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Security for WAP servers, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Security for WAP servers will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-4035757