Over the last years, client-side attacks against web sessions covered a relevant subset of web security incidents. Existing solutions proposed in the literature and by web standards, though interesting, typically address only specific classes of attacks and thus fall short of providing robust foundations to reason on web authentication security. In this thesis we provide such foundations by introducing a novel notion of web session integrity, which allows to capture many existing attacks and spot some new ones. We present FF+, a formal model of a security-enhanced browser that provides a complete and provably sound enforcement of web session integrity. Our theory serves as a basis for the development of SessInt, a client-side solution, implemented as a Google Chrome extension, which provides a level of security very close to FF+, while keeping an eye at usability and user experience.
Enforcing Session Integrity in the World "Wild" Web
Tempesta, Mauro
2015/2016
Abstract
Over the last years, client-side attacks against web sessions covered a relevant subset of web security incidents. Existing solutions proposed in the literature and by web standards, though interesting, typically address only specific classes of attacks and thus fall short of providing robust foundations to reason on web authentication security. In this thesis we provide such foundations by introducing a novel notion of web session integrity, which allows to capture many existing attacks and spot some new ones. We present FF+, a formal model of a security-enhanced browser that provides a complete and provably sound enforcement of web session integrity. Our theory serves as a basis for the development of SessInt, a client-side solution, implemented as a Google Chrome extension, which provides a level of security very close to FF+, while keeping an eye at usability and user experience.File | Dimensione | Formato | |
---|---|---|---|
827400-1176891.pdf
accesso aperto
Tipologia:
Altro materiale allegato
Dimensione
1.15 MB
Formato
Adobe PDF
|
1.15 MB | Adobe PDF | Visualizza/Apri |
I documenti in UNITESI sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/20.500.14247/20967