• DocumentCode
    1753617
  • Title

    Protecting cookies from Cross Site Script attacks using Dynamic Cookies Rewriting technique

  • Author

    Putthacharoen, Rattipong ; Bunyatnoparat, Pratheep

  • Author_Institution
    Dept. of Comput. Eng., King Mongkut´´s Inst. of Technol. Ladkrabang, Bangkok, Thailand
  • fYear
    2011
  • fDate
    13-16 Feb. 2011
  • Firstpage
    1090
  • Lastpage
    1094
  • Abstract
    Web applications often use cookies for maintaining an authentication state between users and web applications, these cookies are typically sent to the users by the web applications after the users have been successfully authenticated. Every subsequent request that contains the valid cookies will be automatically allowed by the web applications without any further authentication. The cookies are used to both identify and authenticate the users; therefore they are an interesting target for potential attackers. Cross Site Scripting attack (XSS for short) is one of popular attacks which is often used to steal the cookies from a browser´s database. In this paper, we introduce a new technique called “Dynamic Cookies Rewriting”, this technique aims to render the cookies useless for XSS attacks. Our technique is implemented in a web proxy where it will automatically rewrite the cookies that are sent back and forth between the users and the web applications. With our technique in place, the cookies at the browser´s database now are not valid for the web applications; therefore the XSS attack will not be able to impersonate the users using stolen cookies.
  • Keywords
    Internet; authorisation; Web applications; Web proxy; XSS attacks; authentication state; browser database; cookies protection; cross site script attacks; dynamic cookies rewriting technique; Authentication; Browsers; Databases; Protocols; Web server; Cookies; Cross Site Script Attacks; HTTP and HTTPs; Web Proxy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Communication Technology (ICACT), 2011 13th International Conference on
  • Conference_Location
    Seoul
  • ISSN
    1738-9445
  • Print_ISBN
    978-1-4244-8830-8
  • Type

    conf

  • Filename
    5745998