首页> 外文会议>International Conference on Financial Cryptography and Data Security >Defeating Cross-Site Request Forgery Attacks with Browser-Enforced Authenticity Protection
【24h】

Defeating Cross-Site Request Forgery Attacks with Browser-Enforced Authenticity Protection

机译:击败跨站点请求伪造攻击与浏览器强制性的真实性保护

获取原文

摘要

A cross site request forgery (CSRF) attack occurs when a user's web browser is instructed by a malicious webpage to send a request to a vulnerable web site, resulting in the vulnerable web site performing actions not intended by the user. CSRF vulnerabilities are very common, and consequences of such attacks are most serious with financial websites. We recognize that CSRF attacks are an example of the confused deputy problem, in which the browser is viewed by websites as the deputy of the user, but may be tricked into sending requests that violate the user's intention. We propose Browser-Enforced Authenticity Protection (BEAP), a browser-based mechanism to defend against CSRF attacks. BEAP infers whether a request reflects the user's intention and whether an authentication token is sensitive, and strips sensitive authentication tokens from any request that may not reflect the user's intention. The inference is based on the information about the request (e.g., how the request is triggered and crafted) and heuristics derived from analyzing real-world web applications. We have implemented BEAP as a Firefox browser extension, and show that BEAP can effectively defend against the CSRF attacks and does not break the existing web applications.
机译:当恶意网页指示用户的Web浏览器将请求发送到漏洞的网站时,发生跨站点请求伪造(CSRF)攻击,从而导致易受攻击的网站执行用户不打算的动作。 CSRF漏洞非常普遍,这种攻击的后果最严重的金融网站。我们认识到CSRF攻击是困惑的副问题的示例,其中浏览器被网站视为用户的副手,但是可以被欺骗到发送违反用户意图的请求。我们提出了浏览器强制性的真实性保护(BEAP),这是一种基于浏览器的机制来防御CSRF攻击。 BEAP Infers是一个请求是否反映了用户的意图以及身份验证令牌是否敏感,并且从任何可能不反映用户意图的任何请求中都可以使用敏感的身份验证令牌。推断基于关于请求的信息(例如,如何如何触发并制作触发和制作的请求)和从分析现实世界Web应用程序的启发式训练。我们已经实现了BEPP作为Firefox浏览器扩展,并显示BEAP可以有效地防御CSRF攻击,并且不会破坏现有的Web应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号