z-logo
open-access-imgOpen Access
Browser protection against cross-site request forgery
Author(s) -
Wim Maes,
Thomas Heyman,
Lieven Desmet,
Wouter Joosen
Publication year - 2009
Publication title -
lirias (ku leuven)
Language(s) - English
Resource type - Conference proceedings
DOI - 10.1145/1655077.1655081
Subject(s) - computer science , context (archaeology) , world wide web , web server , enforcement , computer security , web application , client side , security policy , web browser , client side scripting , web service , web api , the internet , biology , law , political science , paleontology
As businesses are opening up to the web, securing their web applicationsbecomes paramount. Nevertheless, the number of web application attacks isconstantly increasing. Cross-Site Request Forgery (CSRF) is one of the moreserious threats to web applications that gained a lot of attention lately. Itallows an attacker to perform malicious authorized actions originating in theend-users browser, without his knowledge. This paper presents a client-sidepolicy enforcement framework to transparently protect the end-user againstCSRF. To do so, the framework monitors all outgoing web requests within thebrowser and enforces a configurable cross-domain policy. The default policy iscarefully selected to transparently operate in a web 2.0 context. In addition,the paper also proposes an optional server-side policy to improve the accuracyof the client-side policy enforcement. A prototype is implemented as a Firefoxextension, and is thoroughly evaluated in a web 2.0 context.status: publishe

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here
Accelerating Research

Address

John Eccles House
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom