【24h】

Enhancing the Security of Cookies

机译:增强Cookie的安全性

获取原文

摘要

Cookies are pieces of information generated by a Web server to be stored in a user's machine. The information in cookies can range from selected items in a user's shopping cart to authentication information used for accessing restricted pages. While cookies are clearly very useful, they can also be abused. In this paper, security threats that cookies can pose to a user are identified, as are the security requirements necessary to defeat them. Various options to meet the security requirements are then examined. Proposed user-controlled approaches and their implementations are presented and compared with a server-controlled approach, particularly the 'Secure Cookies' method, to illustrate the relative advantages and disadvantages of the two approaches.
机译:Cookie是由Web服务器生成的信息,以存储在用户的计算机中。 Cookie中的信息可以从用户购物车中的所选项目的范围内,以进行用于访问受限页面的身份验证信息。虽然饼干显然非常有用,但它们也可以滥用。在本文中,识别Cookie可以对用户姿势姿势的安全威胁,因为打败它们所需的安全要求是必要的。然后检查各种符合安全要求的选项。提出并将其实现提出并与服务器控制的方法,特别是“安全饼干”方法进行了比较,并且呈现了其实现,以说明两种方法的相对优缺点和缺点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号