首页    期刊浏览 2024年11月26日 星期二
登录注册

文章基本信息

  • 标题:Building a Robust Client-Side Protection Against Cross Site Request Forgery
  • 本地全文:下载
  • 作者:Abdalla AlAmeen
  • 期刊名称:International Journal of Advanced Computer Science and Applications(IJACSA)
  • 印刷版ISSN:2158-107X
  • 电子版ISSN:2156-5570
  • 出版年度:2015
  • 卷号:6
  • 期号:6
  • DOI:10.14569/IJACSA.2015.060610
  • 出版社:Science and Information Society (SAI)
  • 摘要:In recent years, the web has been an indispensable part of business all over the world and web browsers have become the backbones of today's systems and applications. Unfortunately, the number of web application attacks has increased a great deal, so the matter of concern is securing web applications. One of the most serious cyber-attacks has been by cross site request forgery (CSRF). CSRF has been recognized among the major threats to web applications and among the top ten worst vulnerabilities for web applications. In a CSRF attack, an attacker takes liberty be authorized to take a sensitive action on a target website on behalf of a user without his knowledge. This paper, providing an overview about CSRF attack, describes the various possible attacks, the developed solutions, and the risks in the current preventive techniques. This paper comes up with a highly perfect protection mechanism against reflected CSRF called RCSR. RCSR is a tool gives computer users with full control on the attack. RCSR tool relies on specifying HTTP request source, whether it comes from different tab or from the same one of a valid user, it observes and intercepts every request that is passed through the user’s browser and extracts session information, post the extracted information to the Server, then the server create a token for user's session. We checked the working of RCSR extension, our evaluation results show that it is working well and it successfully protects web applications against reflected CSRF.
  • 关键词:thesai; IJACSA; thesai.org; journal; IJACSA papers; Security; Reflected CSRF; client-side protection; tab ID; token
国家哲学社会科学文献中心版权所有