CA2510633C - Verification de la liste de controle d'acces - Google Patents

Verification de la liste de controle d'acces Download PDF

Info

Publication number
CA2510633C
CA2510633C CA2510633A CA2510633A CA2510633C CA 2510633 C CA2510633 C CA 2510633C CA 2510633 A CA2510633 A CA 2510633A CA 2510633 A CA2510633 A CA 2510633A CA 2510633 C CA2510633 C CA 2510633C
Authority
CA
Canada
Prior art keywords
web
application
web application
access control
request
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CA2510633A
Other languages
English (en)
Other versions
CA2510633A1 (fr
Inventor
Marc Graveline
Ulf Viney
Matt Masson
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Palo Alto Networks Inc
Original Assignee
International Business Machines Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by International Business Machines Corp filed Critical International Business Machines Corp
Priority to CA2510633A priority Critical patent/CA2510633C/fr
Publication of CA2510633A1 publication Critical patent/CA2510633A1/fr
Application granted granted Critical
Publication of CA2510633C publication Critical patent/CA2510633C/fr
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0245Filtering by information in the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/101Access control lists [ACL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/102Entity profiles

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer And Data Communications (AREA)

Abstract

Une méthode et un système pour vérifier automatiquement une liste de contrôle d'accès pendant les transferts de données entre un navigateur Web client et un serveur Web. La méthode et le système facilitent la vérification d'une liste de contrôle d'accès par un pare-feu d'application, indépendant de l'application Web. Les règles, sur lesquelles s'inspire la vérification, peuvent être facilement mises à jour sans toucher l'application Web.
CA2510633A 2005-06-23 2005-06-23 Verification de la liste de controle d'acces Active CA2510633C (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CA2510633A CA2510633C (fr) 2005-06-23 2005-06-23 Verification de la liste de controle d'acces

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CA2510633A CA2510633C (fr) 2005-06-23 2005-06-23 Verification de la liste de controle d'acces

Publications (2)

Publication Number Publication Date
CA2510633A1 CA2510633A1 (fr) 2006-12-23
CA2510633C true CA2510633C (fr) 2010-11-09

Family

ID=39343578

Family Applications (1)

Application Number Title Priority Date Filing Date
CA2510633A Active CA2510633C (fr) 2005-06-23 2005-06-23 Verification de la liste de controle d'acces

Country Status (1)

Country Link
CA (1) CA2510633C (fr)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101345758B (zh) * 2008-08-14 2012-09-05 中兴通讯股份有限公司 报表归一化处理方法、装置和系统
US9122870B2 (en) 2011-09-21 2015-09-01 SunStone Information Defense Inc. Methods and apparatus for validating communications in an open architecture system

Also Published As

Publication number Publication date
CA2510633A1 (fr) 2006-12-23

Similar Documents

Publication Publication Date Title
US7475138B2 (en) Access control list checking
US6981143B2 (en) System and method for providing connection orientation based access authentication
AU2002252371B2 (en) Application layer security method and system
EP1634175B1 (fr) Systeme de securite de commande d'acces multicouche
US7882555B2 (en) Application layer security method and system
US20070150574A1 (en) Method for detecting, monitoring, and controlling web services
US8689295B2 (en) Firewalls for providing security in HTTP networks and applications
EP2144420B1 (fr) Filtrage de sécurité d'application Web
US7542957B2 (en) Rich Web application input validation
US20080178278A1 (en) Providing A Generic Gateway For Accessing Protected Resources
US9178705B2 (en) Method and system for stateless validation
US20080256257A1 (en) Systems and methods for reflecting messages associated with a target protocol within a network
AU2002252371A1 (en) Application layer security method and system
US7765310B2 (en) Opaque cryptographic web application data protection
US8996715B2 (en) Application firewall validation bypass for impromptu components
CA2510633C (fr) Verification de la liste de controle d'acces
CA2512931A1 (fr) Validation d'entree d'application web riche
Cisco Cisco Intrusion Detection System Signature Engines Version 3.1
Richardson The development of a database taxonomy of vulnerabilities to support the study of denial of service attacks
CA2584940A1 (fr) Methode et systeme de validation sans etat
Holtkamp The role of XML firewalls for web services
Cheng et al. A complete solution for highly secure data exchange: lock-keeper and its advancements
Demchenko White collar Attacks on Web Services and Grids
Cremonini et al. Semantics-aware perimeter protection
CA2551034A1 (fr) Contournement de validation de pare-feu pour elements impromptus

Legal Events

Date Code Title Description
EEER Examination request