Protecting Cookies from Unauthorized Modification by Trusted Domain Verification

碩士 === 國立交通大學 === 資訊科學與工程研究所 === 100 === HTTP Cookie is a well-known mechanism for the storage of session and authentication information. However, the current cookie standard does not provide robust integrity protection. Session fixation and cookie eviction are two famous attacks based on the lack o...

Full description

Bibliographic Details
Main Authors: Chung, Kai-Jen, 鍾凱任
Other Authors: Shieh, Shiuh-Pyng
Format: Others
Language:en_US
Published: 2012
Online Access:http://ndltd.ncl.edu.tw/handle/50103418472669475985
id ndltd-TW-100NCTU5394130
record_format oai_dc
spelling ndltd-TW-100NCTU53941302016-03-28T04:20:52Z http://ndltd.ncl.edu.tw/handle/50103418472669475985 Protecting Cookies from Unauthorized Modification by Trusted Domain Verification 基於信任網域驗證之憑證檔案變更保護機制 Chung, Kai-Jen 鍾凱任 碩士 國立交通大學 資訊科學與工程研究所 100 HTTP Cookie is a well-known mechanism for the storage of session and authentication information. However, the current cookie standard does not provide robust integrity protection. Session fixation and cookie eviction are two famous attacks based on the lack of integrity protection for cookies. With cookie sharing technique, attackers at untrusted subdomains of a trusted web site can launch these attacks. This paper proposes a trusted domain verification scheme to equip browsers with the ability to identify unauthorized modifications of authentication cookies. Since web administrators can divide domains in a web site into trusted domains and untrusted domains respectively, browsers can block unauthorized accesses with this information. In contrast to the conventional schemes which can only detect attacks or restrict cookie sharing, trusted domain verification can prevent both session fixation and cookie eviction attacks without breaking the functionality of cookie sharing. The effectiveness and overhead of the proposed scheme is also evaluated. Shieh, Shiuh-Pyng 謝續平 2012 學位論文 ; thesis 37 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立交通大學 === 資訊科學與工程研究所 === 100 === HTTP Cookie is a well-known mechanism for the storage of session and authentication information. However, the current cookie standard does not provide robust integrity protection. Session fixation and cookie eviction are two famous attacks based on the lack of integrity protection for cookies. With cookie sharing technique, attackers at untrusted subdomains of a trusted web site can launch these attacks. This paper proposes a trusted domain verification scheme to equip browsers with the ability to identify unauthorized modifications of authentication cookies. Since web administrators can divide domains in a web site into trusted domains and untrusted domains respectively, browsers can block unauthorized accesses with this information. In contrast to the conventional schemes which can only detect attacks or restrict cookie sharing, trusted domain verification can prevent both session fixation and cookie eviction attacks without breaking the functionality of cookie sharing. The effectiveness and overhead of the proposed scheme is also evaluated.
author2 Shieh, Shiuh-Pyng
author_facet Shieh, Shiuh-Pyng
Chung, Kai-Jen
鍾凱任
author Chung, Kai-Jen
鍾凱任
spellingShingle Chung, Kai-Jen
鍾凱任
Protecting Cookies from Unauthorized Modification by Trusted Domain Verification
author_sort Chung, Kai-Jen
title Protecting Cookies from Unauthorized Modification by Trusted Domain Verification
title_short Protecting Cookies from Unauthorized Modification by Trusted Domain Verification
title_full Protecting Cookies from Unauthorized Modification by Trusted Domain Verification
title_fullStr Protecting Cookies from Unauthorized Modification by Trusted Domain Verification
title_full_unstemmed Protecting Cookies from Unauthorized Modification by Trusted Domain Verification
title_sort protecting cookies from unauthorized modification by trusted domain verification
publishDate 2012
url http://ndltd.ncl.edu.tw/handle/50103418472669475985
work_keys_str_mv AT chungkaijen protectingcookiesfromunauthorizedmodificationbytrusteddomainverification
AT zhōngkǎirèn protectingcookiesfromunauthorizedmodificationbytrusteddomainverification
AT chungkaijen jīyúxìnrènwǎngyùyànzhèngzhīpíngzhèngdàngànbiàngèngbǎohùjīzhì
AT zhōngkǎirèn jīyúxìnrènwǎngyùyànzhèngzhīpíngzhèngdàngànbiàngèngbǎohùjīzhì
_version_ 1718213433076219904