Preventing cross-site scripting in web-based e-mail
    2.
    发明授权
    Preventing cross-site scripting in web-based e-mail 有权
    防止基于Web的电子邮件中的跨站点脚本

    公开(公告)号:US09049222B1

    公开(公告)日:2015-06-02

    申请号:US13365161

    申请日:2012-02-02

    IPC分类号: H04L29/06 G06F21/56 G06F21/57

    摘要: Cross-site scripting vulnerabilities in a Web browser that may lead to malware execution on a computing device are reduced. The specific vulnerabilities arise from HTML-based e-mails using e-mail service providers (e.g., Hotmail, Gmail, Yahoo) that have unknown or malformed HTML elements and Javascripts. These unknown elements may execute in a browser and cause harm to the computing device. To prevent this, the e-mail is parsed to create a DOM tree. The DOM tree is filtered using a normal element filter. The modified DOM tree is filtered a second time using a script analyzer filter to isolate potentially harmful HTML and Javascript elements. These elements are then emulated to determine which of them are in fact malicious. These malicious elements are then prevented from executing, for example, by preventing the e-mail recipient from opening the e-mail in the browser.

    摘要翻译: Web浏览器中可能导致计算设备上恶意软件执行的跨站点脚本漏洞减少。 特定的漏洞源自使用电子邮件服务提供商(例如Hotmail,Gmail,Yahoo)的HTML电子邮件,其中包含未知或格式错误的HTML元素和Javascript。 这些未知元素可能在浏览器中执行,并对计算设备造成危害。 为了防止这种情况,电子邮件被解析为创建一个DOM树。 使用普通元素过滤器过滤DOM树。 修改后的DOM树第二次使用脚本分析器过滤器进行过滤,以隔离可能有害的HTML和Javascript元素。 然后将这些元素模拟以确定其中哪些实际上是恶意的。 然后,例如通过防止电子邮件接收者在浏览器中打开电子邮件来防止这些恶意元素的执行。

    Protecting computers against data loss involving screen captures
    3.
    发明授权
    Protecting computers against data loss involving screen captures 有权
    保护计算机免遭涉及屏幕捕获的数据丢失

    公开(公告)号:US08826452B1

    公开(公告)日:2014-09-02

    申请号:US13352634

    申请日:2012-01-18

    IPC分类号: G06F7/04

    CPC分类号: G06F21/84

    摘要: Disclosed are methods and apparatus for protecting computers from data loss involving screen capture. Screen capture events are detected in a computer. Documents that are visible on a computer screen are identified. Files of the visible documents are identified and scanned for sensitive data to determine whether the screen capture events are targeting contents of sensitive documents.

    摘要翻译: 公开了用于保护计算机免遭涉及屏幕捕获的数据丢失的方法和装置。 在计算机中检测到屏幕捕获事件。 识别在计算机屏幕上可见的文档。 对可见文件的文件进行识别并扫描敏感数据,以确定屏幕捕获事件是否针对敏感文档的内容。