首页> 外文会议>1st workshop on secure execution of untrusted code >Browser Protection against Cross-Site Request Forgery
【24h】

Browser Protection against Cross-Site Request Forgery

机译:针对跨站点请求伪造的浏览器保护

获取原文
获取原文并翻译 | 示例

摘要

As businesses are opening up to the web, securing their web applications becomes paramount. Nevertheless, the number of web application attacks is constantly increasing. Cross-Site Request Forgery (CSRF) is one of the more serious threats to web applications that gained a lot of attention lately. It allows an attacker to perform malicious authorized actions originating in the end-users browser, without his knowledge. This paper presents a client-side policy enforcement framework to transparently protect the end-user against CSRF. To do so, the framework monitors all outgoing web requests within the browser and enforces a configurable cross-domain policy. The default policy is carefully selected to transparently operate in a web 2.0 context. In addition, the paper also proposes an optional server-side policy to improve the accuracy of the client-side policy enforcement. A prototype is implemented as a Firefox extension, and is thoroughly evaluated in a web 2.0 context.
机译:随着企业向网络开放,保护其网络应用程序变得至关重要。但是,Web应用程序攻击的数量正在不断增加。跨站点请求伪造(CSRF)是对Web应用程序的最严重威胁之一,近来引起了广泛关注。它允许攻击者在不知情的情况下执行源自最终用户浏览器的恶意授权操作。本文提出了一种客户端策略执行框架,以透明地保护最终用户免受CSRF的侵害。为此,框架会监视浏览器中的所有传出Web请求,并强制执行可配置的跨域策略。仔细选择默认策略以在Web 2.0上下文中透明地运行。此外,本文还提出了可选的服务器端策略,以提高客户端策略执行的准确性。原型被实现为Firefox扩展,并在Web 2.0上下文中进行了全面评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号