MX377724B - Método y dispositivo para evitar que un servidor sea atacado. - Google Patents
Método y dispositivo para evitar que un servidor sea atacado.Info
- Publication number
- MX377724B MX377724B MX2018014378A MX2018014378A MX377724B MX 377724 B MX377724 B MX 377724B MX 2018014378 A MX2018014378 A MX 2018014378A MX 2018014378 A MX2018014378 A MX 2018014378A MX 377724 B MX377724 B MX 377724B
- Authority
- MX
- Mexico
- Prior art keywords
- page
- script
- browser
- request
- server
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1466—Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
- H04L63/123—Applying verification of the received information received data contents, e.g. message integrity
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/80—Information retrieval; Database structures therefor; File system structures therefor of semi-structured data, e.g. markup language structured data such as SGML, XML or HTML
- G06F16/83—Querying
- G06F16/835—Query processing
- G06F16/8373—Query execution
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/80—Information retrieval; Database structures therefor; File system structures therefor of semi-structured data, e.g. markup language structured data such as SGML, XML or HTML
- G06F16/83—Querying
- G06F16/838—Presentation of query results
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/90—Details of database functions independent of the retrieved data types
- G06F16/95—Retrieval from the web
- G06F16/955—Retrieval from the web using information identifiers, e.g. uniform resource locators [URL]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/90—Details of database functions independent of the retrieved data types
- G06F16/95—Retrieval from the web
- G06F16/958—Organisation or management of web site content, e.g. publishing, maintaining pages or automatic linking
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/102—Entity profiles
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/108—Network architectures or network communication protocols for network security for controlling access to devices or network resources when the policy decisions are valid for a limited amount of time
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1458—Denial of Service
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/0643—Hash functions, e.g. MD5, SHA, HMAC or f9 MAC
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/321—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
- H04L9/3213—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority using tickets or tokens, e.g. Kerberos
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3236—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
- H04L9/3239—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving non-keyed hash functions, e.g. modification detection codes [MDCs], MD5, SHA or RIPEMD
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- Databases & Information Systems (AREA)
- Data Mining & Analysis (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Multimedia (AREA)
- Power Engineering (AREA)
- Information Transfer Between Computers (AREA)
- Computer And Data Communications (AREA)
- Storage Device Security (AREA)
Abstract
La presente descripción proporciona un método y dispositivo para evitar que un servidor sea atacado, y se relaciona con el campo de tecnologías de seguridad en la red, para resolver un problema de baja seguridad de un servidor. Las soluciones técnicas principales de la presente descripción son las siguientes: asignar de manera dinámica y aleatoria un guión de página que corresponde a una solicitud de página a partir de una pluralidad de guiones de página que corresponden a la solicitud de página, cuando se recibe la solicitud de página enviada por un navegador; enviar el guión de página asignado de manera dinámica y aleatoria al navegador de manera que el navegador ejecute el guión de página para obtener un parámetro de ejecución de guión; determinar si ha expirado la solicitud de verificación de página, cuando se reciba la solicitud de verificación de página enviada por el navegador; y si ha expirado, transmitir información de mensaje de error indicando la expiración de la página; o si no ha expirado, verificar si el parámetro de ejecución de guión incluido en la solicitud de verificación de página es válido; y de no ser válido, rechazar la solicitud de página. La presente descripción se usa principalmente para evitar que el servidor sea atacado.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610377847.0A CN107454041B (zh) | 2016-05-31 | 2016-05-31 | 防止服务器被攻击的方法及装置 |
| PCT/CN2017/080862 WO2017206605A1 (zh) | 2016-05-31 | 2017-04-18 | 防止服务器被攻击的方法及装置 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| MX2018014378A MX2018014378A (es) | 2019-08-12 |
| MX377724B true MX377724B (es) | 2025-03-11 |
Family
ID=60479720
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| MX2018014378A MX377724B (es) | 2016-05-31 | 2017-04-18 | Método y dispositivo para evitar que un servidor sea atacado. |
Country Status (17)
| Country | Link |
|---|---|
| US (2) | US10965689B2 (es) |
| EP (1) | EP3468128B1 (es) |
| JP (1) | JP6859518B2 (es) |
| KR (1) | KR102242219B1 (es) |
| CN (1) | CN107454041B (es) |
| AU (1) | AU2017273371B2 (es) |
| BR (1) | BR112018074497B1 (es) |
| CA (1) | CA3024889C (es) |
| ES (1) | ES2818588T3 (es) |
| MX (1) | MX377724B (es) |
| MY (1) | MY200541A (es) |
| PH (1) | PH12018502495B1 (es) |
| PL (1) | PL3468128T3 (es) |
| RU (1) | RU2734027C2 (es) |
| SG (1) | SG11201810205XA (es) |
| TW (1) | TW201743237A (es) |
| WO (1) | WO2017206605A1 (es) |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107454041B (zh) | 2016-05-31 | 2020-06-02 | 阿里巴巴集团控股有限公司 | 防止服务器被攻击的方法及装置 |
| CN109936575B (zh) * | 2019-03-07 | 2021-11-12 | 北京融链科技有限公司 | 页面访问方法、装置、存储介质及处理器 |
| CN113761489B (zh) * | 2020-06-02 | 2024-01-26 | 共道网络科技有限公司 | 验证方法、装置及设备、存储介质 |
| CN112600863A (zh) * | 2021-03-04 | 2021-04-02 | 南京敏宇数行信息技术有限公司 | 一种安全远程访问系统及方法 |
| US12130710B2 (en) * | 2022-07-27 | 2024-10-29 | Dell Products L.P. | Self-healing data protection system matching system attributes to relevant scripts using weighted attributes |
Family Cites Families (33)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5541996A (en) | 1994-12-12 | 1996-07-30 | Itt Corporation | Apparatus and method for a pseudo-random number generator for high precision numbers |
| US7555529B2 (en) * | 1995-11-13 | 2009-06-30 | Citrix Systems, Inc. | Interacting with software applications displayed in a web page |
| US7373510B2 (en) * | 2000-09-12 | 2008-05-13 | International Business Machines Corporation | System and method for implementing a robot proof Web site |
| US7127608B2 (en) * | 2001-01-12 | 2006-10-24 | Siemens Medical Solutions Health Services Corporation | System and user interface supporting URL processing and concurrent application operation |
| US7949729B2 (en) | 2001-05-31 | 2011-05-24 | Oracle International Corp. | System and method for displaying dynamic page content in a page-caching browser |
| US20020184507A1 (en) * | 2001-05-31 | 2002-12-05 | Proact Technologies Corp. | Centralized single sign-on method and system for a client-server environment |
| US6941512B2 (en) * | 2001-09-10 | 2005-09-06 | Hewlett-Packard Development Company, L.P. | Dynamic web content unfolding in wireless information gateways |
| US20040039994A1 (en) * | 2002-08-22 | 2004-02-26 | Duffy Colm Donal | System and process for communication between Java server pages and servlets |
| US7376732B2 (en) * | 2002-11-08 | 2008-05-20 | Federal Network Systems, Llc | Systems and methods for preventing intrusion at a web host |
| WO2005017769A1 (en) | 2003-08-19 | 2005-02-24 | Rapid Intelligence Pty Ltd | Content system |
| US7516153B2 (en) | 2005-11-29 | 2009-04-07 | Att Intellectual Property I, L.P. | Rendering dynamic data in a web browser |
| WO2007065019A2 (en) | 2005-12-02 | 2007-06-07 | Hillcrest Laboratories, Inc. | Scene transitions in a zoomable user interface using zoomable markup language |
| CN101030860A (zh) * | 2007-02-15 | 2007-09-05 | 华为技术有限公司 | 一种防御通过自动软件对服务器进行攻击的方法和设备 |
| CN101594343B (zh) * | 2008-05-29 | 2013-01-23 | 国际商业机器公司 | 安全提交请求的装置和方法、安全处理请求的装置和方法 |
| CN101437030B (zh) * | 2008-11-29 | 2012-02-22 | 成都市华为赛门铁克科技有限公司 | 一种防止服务器被攻击的方法、检测装置及监控设备 |
| US20100180082A1 (en) | 2009-01-12 | 2010-07-15 | Viasat, Inc. | Methods and systems for implementing url masking |
| KR101061255B1 (ko) * | 2009-04-17 | 2011-09-01 | 주식회사 파이오링크 | 웹 서버와 클라이언트 간의 통신을 감시하는 웹 보안 관리 장치 및 방법 |
| CN101834866B (zh) * | 2010-05-05 | 2013-06-26 | 北京来安科技有限公司 | 一种cc攻击防护方法及其系统 |
| US9912718B1 (en) | 2011-04-11 | 2018-03-06 | Viasat, Inc. | Progressive prefetching |
| RU2477929C2 (ru) * | 2011-04-19 | 2013-03-20 | Закрытое акционерное общество "Лаборатория Касперского" | Система и способ предотвращения инцидентов безопасности на основании рейтингов опасности пользователей |
| CN102981812A (zh) * | 2011-09-07 | 2013-03-20 | 深圳市金蝶中间件有限公司 | 网页脚本语言的执行方法及装置 |
| CN103139138B (zh) * | 2011-11-22 | 2016-02-03 | 飞塔公司 | 一种基于客户端检测的应用层拒绝服务防护方法及系统 |
| JP2013125497A (ja) * | 2011-12-16 | 2013-06-24 | Sony Corp | 情報処理装置、情報処理方法およびプログラム |
| TWI506471B (zh) | 2011-12-27 | 2015-11-01 | Univ Nat Taiwan Science Tech | 跨網站攻擊防範系統及方法 |
| CN103209158A (zh) * | 2012-01-12 | 2013-07-17 | 深圳市宇初网络技术有限公司 | 一种第三方验证方法以及系统 |
| US20130318056A1 (en) * | 2012-05-23 | 2013-11-28 | Sap Ag | Lightweight Integrity Protection for Web Storage-Driven Content Caching |
| US20140053056A1 (en) * | 2012-08-16 | 2014-02-20 | Qualcomm Incorporated | Pre-processing of scripts in web browsers |
| US20140259145A1 (en) * | 2013-03-08 | 2014-09-11 | Barracuda Networks, Inc. | Light Weight Profiling Apparatus Distinguishes Layer 7 (HTTP) Distributed Denial of Service Attackers From Genuine Clients |
| CN104636664B (zh) * | 2013-11-08 | 2018-04-27 | 腾讯科技(深圳)有限公司 | 基于文档对象模型的跨站脚本攻击漏洞检测方法及装置 |
| CN103795786A (zh) * | 2014-01-20 | 2014-05-14 | 杭州百富电子技术有限公司 | 具有web服务功能的嵌入式集中器系统 |
| TW201547247A (zh) * | 2014-06-13 | 2015-12-16 | Vivotek Inc | 網頁認證方法與系統 |
| US9825928B2 (en) * | 2014-10-22 | 2017-11-21 | Radware, Ltd. | Techniques for optimizing authentication challenges for detection of malicious attacks |
| CN107454041B (zh) | 2016-05-31 | 2020-06-02 | 阿里巴巴集团控股有限公司 | 防止服务器被攻击的方法及装置 |
-
2016
- 2016-05-31 CN CN201610377847.0A patent/CN107454041B/zh active Active
-
2017
- 2017-03-15 TW TW106108587A patent/TW201743237A/zh unknown
- 2017-04-18 KR KR1020187036802A patent/KR102242219B1/ko active Active
- 2017-04-18 CA CA3024889A patent/CA3024889C/en active Active
- 2017-04-18 JP JP2018563073A patent/JP6859518B2/ja active Active
- 2017-04-18 PH PH1/2018/502495A patent/PH12018502495B1/en unknown
- 2017-04-18 BR BR112018074497-2A patent/BR112018074497B1/pt active IP Right Grant
- 2017-04-18 AU AU2017273371A patent/AU2017273371B2/en not_active Ceased
- 2017-04-18 MY MYPI2018002021A patent/MY200541A/en unknown
- 2017-04-18 RU RU2018146848A patent/RU2734027C2/ru active
- 2017-04-18 SG SG11201810205XA patent/SG11201810205XA/en unknown
- 2017-04-18 MX MX2018014378A patent/MX377724B/es active IP Right Grant
- 2017-04-18 ES ES17805550T patent/ES2818588T3/es active Active
- 2017-04-18 WO PCT/CN2017/080862 patent/WO2017206605A1/zh not_active Ceased
- 2017-04-18 PL PL17805550T patent/PL3468128T3/pl unknown
- 2017-04-18 EP EP17805550.5A patent/EP3468128B1/en active Active
-
2018
- 2018-11-28 US US16/202,809 patent/US10965689B2/en active Active
-
2019
- 2019-12-20 US US16/722,326 patent/US10986101B2/en active Active
Also Published As
| Publication number | Publication date |
|---|---|
| PH12018502495B1 (en) | 2022-09-30 |
| EP3468128A4 (en) | 2019-04-24 |
| PH12018502495A1 (en) | 2019-04-08 |
| AU2017273371B2 (en) | 2020-12-24 |
| RU2018146848A (ru) | 2020-07-09 |
| BR112018074497B1 (pt) | 2021-11-30 |
| RU2734027C2 (ru) | 2020-10-12 |
| US20200137075A1 (en) | 2020-04-30 |
| RU2018146848A3 (es) | 2020-07-09 |
| EP3468128A1 (en) | 2019-04-10 |
| JP6859518B2 (ja) | 2021-04-14 |
| PL3468128T3 (pl) | 2020-11-16 |
| CA3024889A1 (en) | 2017-12-07 |
| US10965689B2 (en) | 2021-03-30 |
| WO2017206605A1 (zh) | 2017-12-07 |
| MY200541A (en) | 2024-01-02 |
| BR112018074497A2 (pt) | 2019-05-28 |
| CN107454041B (zh) | 2020-06-02 |
| CA3024889C (en) | 2021-06-22 |
| KR20190015327A (ko) | 2019-02-13 |
| US20190109861A1 (en) | 2019-04-11 |
| TW201743237A (zh) | 2017-12-16 |
| EP3468128B1 (en) | 2020-08-19 |
| MX2018014378A (es) | 2019-08-12 |
| US10986101B2 (en) | 2021-04-20 |
| KR102242219B1 (ko) | 2021-04-21 |
| SG11201810205XA (en) | 2018-12-28 |
| CN107454041A (zh) | 2017-12-08 |
| ES2818588T3 (es) | 2021-04-13 |
| AU2017273371A1 (en) | 2018-12-06 |
| JP2019519849A (ja) | 2019-07-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| PH12019501854A1 (en) | Trusted login method, server, and system | |
| PH12018502495A1 (en) | Method and device for preventing server from being attacked | |
| BR112018009007A2 (pt) | método e sistema para processamento de uma transação de protocolo de confiança em uma rede de processamento de transação | |
| PH12018502092A1 (en) | Method and device for registering biometric identity and authenticating biometric identity | |
| MX390158B (es) | Metodo y dispositivo para determinar una autoridad de control en un dispositivo de usuario. | |
| RU2017105861A (ru) | Проверка данных с использованием аттестации в анклаве | |
| PH12019501175A1 (en) | Resource allocation method and device, and electronic payment method | |
| FI20155763A7 (fi) | Menetelmä ja järjestelmä sertifikaatin aitouden varmistamiseksi ssl-protokollaa käyttäen salatussa internet-yhteydessä verkkosivuun | |
| WO2013028901A3 (en) | Authentication process for value transfer machine | |
| GB201313407D0 (en) | Two device authentication mechanism | |
| EP2615568A3 (en) | Device verification for dynamic re-certificating | |
| PH12016501786A1 (en) | Tag management system, tag management method, information provision system, and information provision method, as well as devices and tag used therefor | |
| JP2018506918A5 (es) | ||
| MX355757B (es) | Metodo de negocios que incluye un sistema de desafio-respuesta para autenticar de forma segura interfaces de programa de aplicaciones de software (apis). | |
| HK1243512A1 (zh) | 利用统计分析识别潜在的ddos攻击 | |
| GB2531677A (en) | A network security system | |
| MX2016006176A (es) | Metodo y dispositivo para procesar solicitud. | |
| MX383704B (es) | Método, dispositivo, servidor y sistema para autenticar a un usuario. | |
| SG10201901701XA (en) | Method, device and system for invoking local service assembly by browser | |
| GB2519263A (en) | Prioritized token based arbiter and method | |
| PH12018502397A1 (en) | Processing method for presenting copy attack, and server and client | |
| JP2014526728A5 (es) | ||
| GB2549631A (en) | Method and apparatus for enabling a single sign-on enabled application to enforce an application lock | |
| EP4564790A3 (en) | Network system | |
| WO2017002158A8 (ja) | 認証サーバ、ユーザ端末、コンテンツサーバ及びそれらの制御方法、並びにコンピュータプログラム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| FG | Grant or registration | ||
| PD | Change of proprietorship |
Owner name: ADVANCED NEW TECHNOLOGIES CO., LTD. |