首页> 外文会议>International conference on information security and cryptology >An Approach for Mitigating Potential Threats in Practical SSO Systems
【24h】

An Approach for Mitigating Potential Threats in Practical SSO Systems

机译:减轻实际SSO系统中潜在威胁的方法

获取原文

摘要

With the prosperity of social networking, it becomes much more convenient for a user to sign onto multiple websites with a web-based single sign-on (SSO) account of an identity provider website. According to the implementation of these SSO system, we classify their patterns into two general abstract models: independent SSO model and standard SSO model. In our research, we find both models contain serious vulnerabilities in their credential exchange protocols. By examining five most famous identity provider websites and 17 famous practical service provider websites, we confirm that these potential vulnerabilities of the abstract models can be exploited in the practical SSO systems. With testing on about 1,000 websites in the wild, we are sure that the problem that we find is widely existing in the real world. These vulnerabilities can be attributed to the lack of integrity protection of login credentials. In order to mitigate these threats, we provide an integral protection prototype which help keeping the credential in a secure environment. After finishing the designation, we implement this prototype in our laboratory environment. Furthermore, we deploy extensive experiments for illustrating the protection prototype is effective and efficient.
机译:随着社交网络的繁荣,用户使用身份提供者网站的基于Web的单点登录(SSO)帐户登录多个网站变得更加方便。根据这些SSO系统的实现,我们将其模式分为两个通用的抽象模型:独立SSO模型和标准SSO模型。在我们的研究中,我们发现这两种模型的凭证交换协议中都包含严重的漏洞。通过检查五个最著名的身份提供者网站和17个著名的实际服务提供者网站,我们确认可以在实际的SSO系统中利用这些抽象模型的潜在漏洞。通过在大约1000个网站上进行野外测试,我们可以确定我们发现的问题在现实世界中广泛存在。这些漏洞可归因于缺乏登录凭据的完整性保护。为了减轻这些威胁,我们提供了一个完整的保护原型,可帮助将凭据保存在安全的环境中。完成指定后,我们将在实验室环境中实施该原型。此外,我们部署了广泛的实验来说明保护原型的有效性和效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号