首页> 外文会议>Asia Joint Conference on Information Security >Preventing Abuse of Cookies Stolen by XSS
【24h】

Preventing Abuse of Cookies Stolen by XSS

机译:阻止滥用曲奇饼被XSS偷走了

获取原文

摘要

Cross Site Scripting (XSS) makes victims execute an arbitrary script and leaks out personal information from victims' computers. An adversary can easily get victim's cookies by the XSS attack. If the adversary cannot use the stolen cookies to impersonate the victim, stealing cookie has no meaning. Therefore, we propose a method to prohibit the abuse of stolen cookies in order to make it ineffective to steal cookies through the XXS attack. The proposed method uses onetime password and challenge-response authentication to identify whether a person is a valid owner of the cookie or not.
机译:跨站点脚本(XSS)使受害者执行任意脚本并从受害者的计算机中泄露出个人信息。对手可以通过XSS攻击轻松获得受害者的饼干。如果对手不能使用被盗的饼干来冒充受害者,偷饼干没有意义。因此,我们提出了一种禁止滥用被盗饼干的方法,以使其无效地通过XXS攻击窃取饼干。该方法使用oneTime密码和质询 - 响应身份验证来识别人是否是饼干的有效所有者。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号