...
首页> 外文期刊>International Journal of Information Technology >Prevention of session hijacking using token and session id reset approach
【24h】

Prevention of session hijacking using token and session id reset approach

机译:使用令牌和会话ID重置方法预防会话劫持

获取原文
获取原文并翻译 | 示例
           

摘要

Session hijacking is the term used to describe the theft of user's cookies and make clone of that cookies. The hacker uses packet sniffer to capture traffic between user and the server to steal the cookies which contain session information. The same then be used to impersonate the user and act as actual user on web. In this paper, Token and Session id Reset Approach has been proposed and implemented, to prevent the session hijacking by cookies cloning. Proposed technique uses; session id, token, IP and bowser fingerprints to authenticate the user on the web server. This technique stores token at the client side in local storage and it will not be stored in cookies. It has been observed that the Man In The Middle, Cross Site Scripting, Session fixation, Cookie-stealing malware, Predictable token and session id, Physical data theft, and Cookie Cloning attacks is hard to perform on the proposed approach.
机译:会话劫持是用于描述用户曲奇饼盗窃并制作该饼干的克隆的术语。黑客使用数据包嗅探器来捕获用户和服务器之间的流量,以窃取包含会话信息的cookie。同样的用来旨在模拟用户并充当Web上的实际用户。在本文中,已经提出并实施了令牌和会话ID重置方法,以防止Cookie克隆的会话劫持。提出的技术用途;会话ID,令牌,IP和Bowser指纹,用于在Web服务器上验证用户。此技术在本地存储中的客户端存储令牌,它将不会存储在cookie中。已经观察到中间,跨站点脚本,会话固定,窃取恶意软件,可预测的令牌和会话ID,物理数据盗窃和Cookie克隆攻击的人很难在所提出的方法上执行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号