Protecting Cookies from Unauthorized Modification by Trusted Domain Verification
碩士 === 國立交通大學 === 資訊科學與工程研究所 === 100 === HTTP Cookie is a well-known mechanism for the storage of session and authentication information. However, the current cookie standard does not provide robust integrity protection. Session fixation and cookie eviction are two famous attacks based on the lack o...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | en_US |
Published: |
2012
|
Online Access: | http://ndltd.ncl.edu.tw/handle/50103418472669475985 |
id |
ndltd-TW-100NCTU5394130 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-100NCTU53941302016-03-28T04:20:52Z http://ndltd.ncl.edu.tw/handle/50103418472669475985 Protecting Cookies from Unauthorized Modification by Trusted Domain Verification 基於信任網域驗證之憑證檔案變更保護機制 Chung, Kai-Jen 鍾凱任 碩士 國立交通大學 資訊科學與工程研究所 100 HTTP Cookie is a well-known mechanism for the storage of session and authentication information. However, the current cookie standard does not provide robust integrity protection. Session fixation and cookie eviction are two famous attacks based on the lack of integrity protection for cookies. With cookie sharing technique, attackers at untrusted subdomains of a trusted web site can launch these attacks. This paper proposes a trusted domain verification scheme to equip browsers with the ability to identify unauthorized modifications of authentication cookies. Since web administrators can divide domains in a web site into trusted domains and untrusted domains respectively, browsers can block unauthorized accesses with this information. In contrast to the conventional schemes which can only detect attacks or restrict cookie sharing, trusted domain verification can prevent both session fixation and cookie eviction attacks without breaking the functionality of cookie sharing. The effectiveness and overhead of the proposed scheme is also evaluated. Shieh, Shiuh-Pyng 謝續平 2012 學位論文 ; thesis 37 en_US |
collection |
NDLTD |
language |
en_US |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立交通大學 === 資訊科學與工程研究所 === 100 === HTTP Cookie is a well-known mechanism for the storage of session and authentication information. However, the current cookie standard does not provide robust integrity protection. Session fixation and cookie eviction are two famous attacks based on the lack of integrity protection for cookies. With cookie sharing technique, attackers at untrusted subdomains of a trusted web site can launch these attacks. This paper proposes a trusted domain verification scheme to equip browsers with the ability to identify unauthorized modifications of authentication cookies. Since web administrators can divide domains in a web site into trusted domains and untrusted domains respectively, browsers can block unauthorized accesses with this information. In contrast to the conventional schemes which can only detect attacks or restrict cookie sharing, trusted domain verification can prevent both session fixation and cookie eviction attacks without breaking the functionality of cookie sharing. The effectiveness and overhead of the proposed scheme is also evaluated.
|
author2 |
Shieh, Shiuh-Pyng |
author_facet |
Shieh, Shiuh-Pyng Chung, Kai-Jen 鍾凱任 |
author |
Chung, Kai-Jen 鍾凱任 |
spellingShingle |
Chung, Kai-Jen 鍾凱任 Protecting Cookies from Unauthorized Modification by Trusted Domain Verification |
author_sort |
Chung, Kai-Jen |
title |
Protecting Cookies from Unauthorized Modification by Trusted Domain Verification |
title_short |
Protecting Cookies from Unauthorized Modification by Trusted Domain Verification |
title_full |
Protecting Cookies from Unauthorized Modification by Trusted Domain Verification |
title_fullStr |
Protecting Cookies from Unauthorized Modification by Trusted Domain Verification |
title_full_unstemmed |
Protecting Cookies from Unauthorized Modification by Trusted Domain Verification |
title_sort |
protecting cookies from unauthorized modification by trusted domain verification |
publishDate |
2012 |
url |
http://ndltd.ncl.edu.tw/handle/50103418472669475985 |
work_keys_str_mv |
AT chungkaijen protectingcookiesfromunauthorizedmodificationbytrusteddomainverification AT zhōngkǎirèn protectingcookiesfromunauthorizedmodificationbytrusteddomainverification AT chungkaijen jīyúxìnrènwǎngyùyànzhèngzhīpíngzhèngdàngànbiàngèngbǎohùjīzhì AT zhōngkǎirèn jīyúxìnrènwǎngyùyànzhèngzhīpíngzhèngdàngànbiàngèngbǎohùjīzhì |
_version_ |
1718213433076219904 |