Invention Publication
- Patent Title: DYNAMIC PROTECTION OF WEB FORMS
-
Application No.: US17882436Application Date: 2022-08-05
-
Publication No.: US20240048593A1Publication Date: 2024-02-08
- Inventor: Cedric Hebert , Merve Sahin
- Applicant: SAP SE
- Applicant Address: DE Walldorf
- Assignee: SAP SE
- Current Assignee: SAP SE
- Current Assignee Address: DE Walldorf
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F16/958 ; G06F40/143 ; G06F40/103

Abstract:
The source code of an HTML form can be analyzed to derive parameter rules that are subsequently enforced when apparent content of the HTML form is received. Such parameter rules can be drawn from client-side restrictions that are extracted from the HTML source, which are then enforced to prevent content violating the rules from reaching the backend. A proxy can sit between the application and the apparent browser. Dynamically generated HTML can be supported via a headless browser that mirrors HTML that would be present at a browser. Useful for preventing HTML form-based attacks and identifying clear cases of malicious HTML form requests.
Information query