Abstract. Session cookies constitute one of the main attack targets against client authentication on the Web. To counter that, modern web browsers implement native cookie protection mechanisms based on the Secure and HttpOnly flags. While there is a general understanding about the effectiveness of these defenses, no formal result has so far been proved about the security guarantees they convey. With the present paper we provide the first such result, with a mechanized proof of noninterfer-ence assessing the robustness of the Secure and HttpOnly cookie flags against both web and network attacks. We then develop CookiExt, a browser extension that provides client-side protection against session hi-jacking based on appropriate flagging of sessi...
Browser-based defenses have recently been advocated as an effective mechanism to protect potentially...
Abstract—Enforcing protection at the browser side has recently become a popular approach for securin...
XSS attacks are the number one attacks in the Web applications. Web applications are becoming the do...
Session cookies constitute one of the main attack targets against client authentication on the Web. ...
Session cookies constitute one of the main attack targets against client authentication on the Web. ...
Modern websites set multiple authentication cookies during the login process to allow users to rema...
Sessions on the web are fragile. They have been attacked successfully in many ways, by network-level...
Abstract. Sessions on the web are fragile. They have been attacked suc-cessfully in many ways, by ne...
Since cookies act as the only proof of a user identity, web sessions are particularly vulnerable to ...
© Springer International Publishing Switzerland 2014. Sessions on the web are fragile. They have bee...
Browser-based defenses have recently been advocated as an effective mechanism to protect potentially...
The web has become a new, highly interactive medium. Many modern websites provide their users with t...
Abstract: In early days, web pages always use a state for keeping an authentication state between br...
International audienceThe web is the most wide-spread and de facto distributed platform, with a plet...
To my mother. Web applications are the dominant means to provide access to millions of on-line servi...
Browser-based defenses have recently been advocated as an effective mechanism to protect potentially...
Abstract—Enforcing protection at the browser side has recently become a popular approach for securin...
XSS attacks are the number one attacks in the Web applications. Web applications are becoming the do...
Session cookies constitute one of the main attack targets against client authentication on the Web. ...
Session cookies constitute one of the main attack targets against client authentication on the Web. ...
Modern websites set multiple authentication cookies during the login process to allow users to rema...
Sessions on the web are fragile. They have been attacked successfully in many ways, by network-level...
Abstract. Sessions on the web are fragile. They have been attacked suc-cessfully in many ways, by ne...
Since cookies act as the only proof of a user identity, web sessions are particularly vulnerable to ...
© Springer International Publishing Switzerland 2014. Sessions on the web are fragile. They have bee...
Browser-based defenses have recently been advocated as an effective mechanism to protect potentially...
The web has become a new, highly interactive medium. Many modern websites provide their users with t...
Abstract: In early days, web pages always use a state for keeping an authentication state between br...
International audienceThe web is the most wide-spread and de facto distributed platform, with a plet...
To my mother. Web applications are the dominant means to provide access to millions of on-line servi...
Browser-based defenses have recently been advocated as an effective mechanism to protect potentially...
Abstract—Enforcing protection at the browser side has recently become a popular approach for securin...
XSS attacks are the number one attacks in the Web applications. Web applications are becoming the do...