首页> 外文会议>World Conference on Information Systems and Technologies >Implementation of Web Browser Extension for Mitigating CSRF Attack
【24h】

Implementation of Web Browser Extension for Mitigating CSRF Attack

机译:用于缓解CSRF攻击的Web浏览器扩展的实现

获取原文

摘要

CSRF is one of the most serious cyber-attacks and has been recognized among the major threats and among the top ten worst vulnerabilities of web applications. CSRF attack occurs when the attacker takes the advantages of implicit authentication mechanisms of HTTP protocol and cached credentials in the browser to execute a sensitive action on a target website behalf of an authenticated user without his knowledge. In this paper, we present a CSRF protection mechanism that can be added to Google Chrome browser as an extension. Our tool "CSRF Detector" is purely implemented on the client-side to defeat the attacker attempt to perform CSRF attacks by analyzing web requests and web pages content to detect all the basic and advanced CSRF attacks. Our evaluation result shows that CSRF Detector extension successfully detects all the generated attacks and it has the ability to protect users and web applications against CSRF attacks with no false positive.
机译:CSRF是最严重的网络攻击之一,并且在主要威胁中得到了认可,并且在Web应用程序的十大漏洞中得到了认可。 CSRF攻击发生在攻击者HTTP协议的隐式身份验证机制和浏览器中的缓存凭据的优势时,在没有他的知识的情况下代表身份验证的用户在目标网站上执行敏感操作。在本文中,我们介绍了一个CSRF保护机制,可以将Google Chrome浏览器添加到谷歌浏览器中。我们的工具“CSRF探测器”纯粹在客户端实现,以击败攻击者尝试通过分析Web请求和网页内容来执行CSRF攻击,以检测所有基本和高级CSRF攻击。我们的评估结果表明,CSRF检测器扩展成功检测所有生成的攻击,它有能力保护用户和Web应用程序免受CSRF攻击的攻击,没有误报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号