【24h】

CSRF Vulnerabilities and Defensive Techniques

机译:CSRF漏洞和防御技术

获取原文
       

摘要

Web applications are now part of day to day life due to their user friendly environment as well as advancement of technology to provide internet facilities, but these web applications brought lot of threats with them and these threats are continuously growing, one of the these threat is Cross Site Request Forgery(CSRF). CSRF attack is immerged as serious threat to web applications which based on the vulnerabilities present in the normal request response pattern of HTTP protocol. It is difficult to detect and hence it is present in most of the existing web applications. CSRF attack occurs when a malicious web site causes a user’s web browser to perform an unwanted action on a trusted site. It is listed in OWASP’s top ten Web Application attacks list. In this survey paper we will study CSRF attack, CSRF vulnerabilities and its defensive measures. We have compared various defense mechanisms to analyse the best defense mechanism. This study will help us to build strong and robust CSRF protection mechanism.
机译:Web应用程序由于其用户友好的环境以及提供Internet设施的技术进步而如今已成为日常生活的一部分,但是这些Web应用程序带来了很多威胁,并且这些威胁正在持续增长,其中一种威胁是跨站点请求伪造(CSRF)。 CSRF攻击被视为对Web应用程序的严重威胁,基于HTTP协议的正常请求响应模式中存在的漏洞。它很难检测,因此它存在于大多数现有的Web应用程序中。当恶意网站导致用户的网络浏览器在受信任的网站上执行有害操作时,就会发生CSRF攻击。它在OWASP的十大Web应用程序攻击列表中列出。在本调查文件中,我们将研究CSRF攻击,CSRF漏洞及其防御措施。我们比较了各种防御机制,以分析最佳防御机制。这项研究将帮助我们建立强大而强大的CSRF保护机制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号