Over the last years, client-side attacks against web sessions covered a relevant subset of web security incidents. Existing solutions proposed in the literature and by web standards, though interesting, typically address only specific classes of attacks and thus fall short of providing robust foundations to reason on web authentication security. In this thesis we provide such foundations by introducing a novel notion of web session integrity, which allows to capture many existing attacks and spot some new ones. We present FF+, a formal model of a security-enhanced browser that provides a complete and provably sound enforcement of web session integrity. Our theory serves as a basis for the development of SessInt, a client-side solution, implemented as a Google Chrome extension, which provides a level of security very close to FF+, while keeping an eye at usability and user experience.

Enforcing Session Integrity in the World "Wild" Web

Tempesta, Mauro
2015/2016

Abstract

Over the last years, client-side attacks against web sessions covered a relevant subset of web security incidents. Existing solutions proposed in the literature and by web standards, though interesting, typically address only specific classes of attacks and thus fall short of providing robust foundations to reason on web authentication security. In this thesis we provide such foundations by introducing a novel notion of web session integrity, which allows to capture many existing attacks and spot some new ones. We present FF+, a formal model of a security-enhanced browser that provides a complete and provably sound enforcement of web session integrity. Our theory serves as a basis for the development of SessInt, a client-side solution, implemented as a Google Chrome extension, which provides a level of security very close to FF+, while keeping an eye at usability and user experience.
2015-03-12
File in questo prodotto:
File Dimensione Formato  
827400-1176891.pdf

accesso aperto

Tipologia: Altro materiale allegato
Dimensione 1.15 MB
Formato Adobe PDF
1.15 MB Adobe PDF Visualizza/Apri

I documenti in UNITESI sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14247/20967