首页> 外文会议>Nordic conference on secure IT systems >Prevent Session Hijacking by Binding the Session to the Cryptographic Network Credentials
【24h】

Prevent Session Hijacking by Binding the Session to the Cryptographic Network Credentials

机译:通过将会话绑定到加密网络凭据来防止会话劫持

获取原文

摘要

Many cyber-physical applications are responsible for safety critical or business critical infrastructure. Such applications are often controlled through a web interface. They manage sensitive databases, drive important SCADA systems or represent imperative business processes. A vast majority of such web applications are well-known to be vulnerable to a number of exploits. The focus of this paper is on the vulnerability of session stealing, also called session hijacking. We developed a novel method to prevent session stealing in general. The key idea of the method is binding the securely negotiated communication channel to the application user authentication. For this we introduce a server side reverse proxy which runs independently from the client and server software. The proposed method wraps around the deployed infrastructure and requires no alterations to existing software. This paper discusses the technical encryption issues involved with employing this method. We describe a prototype implementation and motivate the technical choices made. Furthermore, the prototype is validated by applying it to secure the particularly vulnerable BLACKBOARD Learn system, which is a important and critical infrastructural application for our university. We concretely demonstrate how to protect this system against session stealing. Finally, we discuss the application areas of this new method.
机译:许多网络物理应用程序负责安全关键或业务关键的基础结构。此类应用程序通常通过Web界面进行控制。他们管理敏感的数据库,驱动重要的SCADA系统或代表命令性的业务流程。众所周知,绝大多数此类Web应用程序容易受到多种攻击。本文的重点是会话窃取的脆弱性,也称为会话劫持。我们开发了一种新颖的方法来总体上防止会话窃取。该方法的关键思想是将安全协商的通信通道绑定到应用程序用户身份验证。为此,我们介绍了独立于客户端和服务器软件运行的服务器端反向代理。所提出的方法围绕已部署的基础结构进行,并且不需要更改现有软件。本文讨论了使用此方法涉及的技术加密问题。我们描述了原型实现方式,并激发了做出的技术选择。此外,通过将样机用于保护特别脆弱的BLACKBOARD Learn系统来验证该样机,这对于我们的大学而言是重要且至关重要的基础设施应用。我们将具体演示如何保护该系统免受会话窃取。最后,我们讨论了这种新方法的应用领域。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号