发明申请
US20120284767A1 Method for detecting and applying different security policies to active client requests running within secure user web sessions
有权
用于检测和应用不同安全策略的方法,用于在安全用户Web会话中运行的活动客户端请求
- 专利标题: Method for detecting and applying different security policies to active client requests running within secure user web sessions
- 专利标题(中): 用于检测和应用不同安全策略的方法,用于在安全用户Web会话中运行的活动客户端请求
-
申请号: US13101458申请日: 2011-05-05
-
公开(公告)号: US20120284767A1公开(公告)日: 2012-11-08
- 发明人: Christopher John Hockings , Trevor Scott Norvill , Scott Anthony Exton
- 申请人: Christopher John Hockings , Trevor Scott Norvill , Scott Anthony Exton
- 申请人地址: US NY Armonk
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY Armonk
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A method for detecting and applying security policy to active client requests within a secure user session begins by applying a first heuristic to a plurality of requests for a particular resource to identify a pattern indicating of an active client. In one embodiment, the heuristic evaluates a frequency of requests for the particular resource across one or more secure user sessions. Later, upon receipt of a new request for the particular resource, a determination is then made whether the new request is consistent with the pattern. If so, an action is taken with respect to a secure session policy. In one embodiment, the action bypasses the secure session policy, which policy is associated with an inactivity time-out that might otherwise have been triggered upon receipt of the new request. In addition, a second heuristic may be applied to determine whether a response proposed to be returned (in response to the new request) is expected by the active client. If so, the response is returned unaltered. If, however, applying the second heuristic indicates that the response proposed to be returned is not expected by the active client, the response is modified to create a modified response, which is then returned.
公开/授权文献
信息查询