Browser protection against cross-site request forgery
Author(s) -
Wim Maes,
Thomas Heyman,
Lieven Desmet,
Wouter Joosen
Publication year - 2009
Publication title -
lirias (ku leuven)
Language(s) - English
Resource type - Conference proceedings
DOI - 10.1145/1655077.1655081
Subject(s) - computer science , context (archaeology) , world wide web , web server , enforcement , computer security , web application , client side , security policy , web browser , client side scripting , web service , web api , the internet , biology , law , political science , paleontology
As businesses are opening up to the web, securing their web applicationsbecomes paramount. Nevertheless, the number of web application attacks isconstantly increasing. Cross-Site Request Forgery (CSRF) is one of the moreserious threats to web applications that gained a lot of attention lately. Itallows an attacker to perform malicious authorized actions originating in theend-users browser, without his knowledge. This paper presents a client-sidepolicy enforcement framework to transparently protect the end-user againstCSRF. To do so, the framework monitors all outgoing web requests within thebrowser and enforces a configurable cross-domain policy. The default policy iscarefully selected to transparently operate in a web 2.0 context. In addition,the paper also proposes an optional server-side policy to improve the accuracyof the client-side policy enforcement. A prototype is implemented as a Firefoxextension, and is thoroughly evaluated in a web 2.0 context.status: publishe
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom