首页> 外文期刊>International Journal of Computer Trends and Technology >Avoiding Cross Site Request Forgery (CSRF) Attack Using TwoFish Security Approach
【24h】

Avoiding Cross Site Request Forgery (CSRF) Attack Using TwoFish Security Approach

机译:使用TwoFish安全方法避免跨站点请求伪造(CSRF)攻击

获取原文
           

摘要

Security is the most important factor for online users to secure their confidential data. Users are nervous about the security risks of the internet. Identifying Vulnerability has been major challenge to each user in order to rectify it. This paper addresses such type of vulnerability named as Cross Site Request Forgery attack. Basically, an attacker will use CSRF attack to trick a victim into accessing a phishing website or clicking a url link that contains malicious program which performs unwanted action that causes loss of user data. This type of attack is very effectual and dangerous to prevent it. An earlier methodology such as visual cryptography is used to avoid these CSRF attacks. Unfortunately this approach is timeconsuming, as they require manual effort to integrate defense techniques which makes low accuracy rate and it not fulfill the need of the users. CSRF attacks are possible because websites are authenticated by the web browser, not the user. A novel approach “Avoiding CSRF attack using TwoFish security” is proposed to avoid these attacks by which the user can validate the website in an understandable manner. This TwoFish security is an enhanced way to validate the web page and performs authentication in two phases; Firstly MD5 encryption is performed in order to calculate the hash values for url and secondly image based authentication is provided to validate the image of respective url. By using this strategy, the user can easily recognize whether a website is a genuine website or vulnerable website. We are providing experimental results that demonstrate the use of our prototype that provides service oriented authenticated websites to respective clients.
机译:安全性是在线用户保护其机密数据的最重要因素。用户担心互联网的安全风险。为了纠正它,识别漏洞一直是每个用户的主要挑战。本文解决了称为跨站点请求伪造攻击的此类漏洞。基本上,攻击者将使用CSRF攻击来诱骗受害者访问钓鱼网站或单击包含恶意程序的URL链接,这些恶意程序会执行有害的操作,从而导致用户数据丢失。这种类型的攻击非常有效且很危险,无法阻止。为了避免这些CSRF攻击,使用了较早的方法,例如视觉密码学。不幸的是,这种方法很耗时,因为他们需要人工来整合防御技术,这使得准确率低并且不能满足用户的需求。 CSRF攻击是可能的,因为网站是通过Web浏览器而非用户进行身份验证的。为了避免这些攻击,用户提出了一种新颖的方法“使用TwoFish安全性避免CSRF攻击”,用户可以通过这种攻击以易于理解的方式验证网站。 TwoFish安全性是验证网页和执行身份验证的增强方法,分两个阶段进行;首先,执行MD5加密,以计算url的哈希值,然后提供基于图像的身份验证,以验证相应url的图像。通过使用此策略,用户可以轻松识别网站是正版网站还是易受攻击的网站。我们提供的实验结果证明了我们原型的使用,该原型向各个客户提供了面向服务的经过身份验证的网站。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号