- 专利标题: Identifying webpages accessible by unauthorized users via URL guessing or network sniffing
-
申请号: US15995823申请日: 2018-06-01
-
公开(公告)号: US10460002B2公开(公告)日: 2019-10-29
- 发明人: Michael Bender , David E. Nachman , Michael P. Shute , Keith R. Walker
- 申请人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 申请人地址: US NY Armonk
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY Armonk
- 代理机构: Roberts Mlotkowski Safran Cole & Calderon, P.C.
- 代理商 William Hartwell; Andrew D. Wright
- 主分类号: H04L9/00
- IPC分类号: H04L9/00 ; G06F16/955 ; H04L29/08 ; H04L29/06 ; G06F16/84
摘要:
A computer-implemented method includes: generating a first list of uniform resource locators (URLs) available on a page when accessed using privileged credentials; storing one or more first URL outputs associated with the first list of URLs including the content of webpages accessed using the privileged credentials; generating a second list of URLs when accessed using non-privileged credentials; generating a third list of URLs, wherein the third list of URLs includes URLs included in the first list of URLs and not included in the second list of URLs; storing a second URL output including content of a webpage mapped to a particular URL in the third list of URLs when the particular URL is accessed using the non-privileged credentials; determining that the second URL output matches a particular first URL output associated with the particular URL; and outputting an alert identifying that the webpage is accessible by an unauthorized user.
公开/授权文献
信息查询