HIERARCHICAL RULE DEVELOPMENT AND BINDING FOR WEB APPLICATION SERVER FIREWALL
    11.
    发明申请
    HIERARCHICAL RULE DEVELOPMENT AND BINDING FOR WEB APPLICATION SERVER FIREWALL 有权
    WEB应用服务器防火墙的分层规则开发与绑定

    公开(公告)号:US20120304275A1

    公开(公告)日:2012-11-29

    申请号:US13114315

    申请日:2011-05-24

    IPC分类号: G06F21/00

    摘要: At least one of an HTTP request message and an HTTP response message is intercepted. A corresponding HTTP message model is identified. The HTTP message model includes a plurality of message model sections. Additional steps include parsing a representation of the at least one of an HTTP request message and an HTTP response message into message sections in accordance with the message model sections of the HTTP message model; and binding a plurality of security rules to the message model sections. The plurality of security rules each specify at least one action to be taken in response to a given condition. The given condition is based, at least in part, on a corresponding given one of the message sections. A further step includes processing the at least one of an HTTP request message and an HTTP response message in accordance with the plurality of security rules. Techniques for developing rules for a web application server firewall are also provided.

    摘要翻译: HTTP请求消息和HTTP响应消息中的至少一个被拦截。 识别出相应的HTTP消息模型。 HTTP消息模型包括多个消息模型部分。 附加步骤包括根据HTTP消息模型的消息模型部分将HTTP请求消息和HTTP响应消息中的至少一个的表示解析成消息部分; 并将多个安全规则绑定到消息模型部分。 多个安全规则每个指定响应于给定条件要采取的至少一个动作。 给定条件至少部分地基于相应给定的一个消息部分。 另一步骤包括根据多个安全规则处理HTTP请求消息和HTTP响应消息中的至少一个。 还提供了开发Web应用服务器防火墙规则的技术。

    Method for source-related risk detection and alert generation
    12.
    发明授权
    Method for source-related risk detection and alert generation 有权
    与源相关的风险检测和警报生成方法

    公开(公告)号:US08171458B2

    公开(公告)日:2012-05-01

    申请号:US12249511

    申请日:2008-10-10

    IPC分类号: G06F9/44

    CPC分类号: G06F8/71

    摘要: A method and system for detecting a source-related risk and generating an alert concerning the source-related risk are disclosed. Criteria of the source-related risk are defined. Thresholds associated with the source-related risk are defined. Every operation on an object is detected. If an operation on an object satisfies a criterion among the criteria or if the operation causes to exceed a threshold among the thresholds, an alert is generated for the operation.

    摘要翻译: 公开了一种用于检测源相关风险并产生与源相关风险有关的警报的方法和系统。 定义与源相关风险的标准。 定义与源相关风险相关的阈值。 检测到对象上的每个操作。 如果对象上的操作满足标准中的标准,或者如果操作导致阈值之间超过阈值,则为该操作生成警报。

    METHOD FOR SOURCE-RELATED RISK DETECTION AND ALERT GENERATION
    14.
    发明申请
    METHOD FOR SOURCE-RELATED RISK DETECTION AND ALERT GENERATION 有权
    用于与源相关的风险检测和警报发生的方法

    公开(公告)号:US20100095277A1

    公开(公告)日:2010-04-15

    申请号:US12249511

    申请日:2008-10-10

    IPC分类号: G06F9/44

    CPC分类号: G06F8/71

    摘要: A method and system for detecting a source-related risk and generating an alert concerning the source-related risk are disclosed. Criteria of the source-related risk are defined. Thresholds associated with the source-related risk are defined. Every operation on an object is detected. If an operation on an object satisfies a criterion among the criteria or if the operation causes to exceed a threshold among the thresholds, an alert is generated for the operation.

    摘要翻译: 公开了一种用于检测源相关风险并产生与源相关风险有关的警报的方法和系统。 定义与源相关风险的标准。 定义与源相关风险相关的阈值。 检测到对象上的每个操作。 如果对象上的操作满足标准中的标准,或者如果操作导致阈值之间超过阈值,则为操作生成警报。

    METHOD OF BAND GROUP PARTITION FOR WIDEBAND AUDIO CODEC
    16.
    发明申请
    METHOD OF BAND GROUP PARTITION FOR WIDEBAND AUDIO CODEC 审中-公开
    宽带音频编解码带组分割方法

    公开(公告)号:US20070033011A1

    公开(公告)日:2007-02-08

    申请号:US11458207

    申请日:2006-07-18

    IPC分类号: G10L19/14

    CPC分类号: G10L19/0204 G10L19/24

    摘要: This invention discloses a method of frequency band group partition for wideband audio codec. It can determine the initial frequency band group partition within the whole effective range of frequency bands. It further subdivides frequency band groups based on the initial partition. Instead of the iteration-based algorithm, this invention applies the 1-from-2 and 1-from-3 criterions to accomplish the fast partition with at most 3 subdivisions. This invention implements the fast partition for frequency band group without the loss of the coding efficiency. By applying this fast partition method, one can greatly reduce the computational complexity and significantly improve the coding performance.

    摘要翻译: 本发明公开了一种用于宽带音频编解码器的频带分组方法。 它可以确定频带整个有效范围内的初始频带组分区。 它会根据初始分区进一步细分频段组。 本发明代替基于迭代的算法,应用1从2和1从3的标准来完成具有最多3个细分的快速分区。 本发明实现了对于频带组的快速划分,而不损失编码效率。 通过应用这种快速分割方法,可以大大降低计算复杂度并显着提高编码性能。

    Hierarchical rule development and binding for web application server firewall
    19.
    发明授权
    Hierarchical rule development and binding for web application server firewall 有权
    Web应用服务器防火墙的层次规则开发和绑定

    公开(公告)号:US08627442B2

    公开(公告)日:2014-01-07

    申请号:US13114315

    申请日:2011-05-24

    摘要: At least one of an HTTP request message and an HTTP response message is intercepted. A corresponding HTTP message model is identified. The HTTP message model includes a plurality of message model sections. Additional steps include parsing a representation of the at least one of an HTTP request message and an HTTP response message into message sections in accordance with the message model sections of the HTTP message model; and binding a plurality of security rules to the message model sections. The plurality of security rules each specify at least one action to be taken in response to a given condition. The given condition is based, at least in part, on a corresponding given one of the message sections. A further step includes processing the at least one of an HTTP request message and an HTTP response message in accordance with the plurality of security rules. Techniques for developing rules for a web application server firewall are also provided.

    摘要翻译: HTTP请求消息和HTTP响应消息中的至少一个被拦截。 识别出相应的HTTP消息模型。 HTTP消息模型包括多个消息模型部分。 附加步骤包括根据HTTP消息模型的消息模型部分将HTTP请求消息和HTTP响应消息中的至少一个的表示解析成消息部分; 并将多个安全规则绑定到消息模型部分。 多个安全规则每个指定响应于给定条件要采取的至少一个动作。 给定条件至少部分地基于相应给定的一个消息部分。 另一步骤包括根据多个安全规则处理HTTP请求消息和HTTP响应消息中的至少一个。 还提供了开发Web应用服务器防火墙规则的技术。

    METHOD AND APPARATUS FOR SECURITY VALIDATION
    20.
    发明申请
    METHOD AND APPARATUS FOR SECURITY VALIDATION 有权
    用于安全验证的方法和装置

    公开(公告)号:US20120304249A1

    公开(公告)日:2012-11-29

    申请号:US13512642

    申请日:2010-11-05

    IPC分类号: G06F21/00

    摘要: A computer-implemented method, apparatus, and article of manufacture for security validation of a user input in a computer network application. The method includes: providing a subset of security rules of a server-side protection means to a pre-validation component deployed at a client side, so as to enable security validation of a user input on the client side by the pre-validation component; validating the user input based on at least one of the security rules; determining, in response to detecting a user input violation and that a violated security rule has not been provided to the pre-validation component, the user as a first class of users; determining, in response to detecting the user input violation and that the violated security rule has been provided to the pre-validation component, the user as a second class of users; and performing different security protection actions to the first and second class of users.

    摘要翻译: 用于计算机网络应用中的用户输入的安全验证的计算机实现的方法,装置和制品。 该方法包括:将服务器侧保护装置的安全规则的子集提供给部署在客户机侧的预验证组件,以便通过预验证组件实现客户端侧的用户输入的安全验证; 基于所述安全规则中的至少一个验证所述用户输入; 确定响应于检测到用户输入违例并且未将所述违反的安全规则提供给所述预验证组件,所述用户作为第一类用户; 响应于检测到所述用户输入违例并且所述违反的安全规则已经被提供给所述预验证部件,所述用户作为第二类用户; 并对第一类和第二类用户执行不同的安全保护动作。