DocumentCode :
554613
Title :
A conceptual model for preventing web bypass vulnerabilities
Author :
Zhiqiang Wei ; Kaiyuan Shi ; Dongning Jia
Author_Institution :
Dept. of Comput. Sci., Ocean Univ. of China, Qingdao, China
Volume :
5
fYear :
2011
fDate :
12-14 Aug. 2011
Firstpage :
2287
Lastpage :
2290
Abstract :
This paper provides a conceptual model for reducing bypass vulnerabilities in web applications. The typical and primary two kinds of bypass vulnerabilities are authentication and access control vulnerabilities. Authentication attacks occur when a web application authenticates users incorrectly and grants access for users without appropriate credentials. Access control attacks happen when access control check is incorrect or missing, allowing unauthorized access to privileged resources. Such attacks are getting increasingly common and have occurred in many famous web applications such as IIS and WordPress, and 14% of surveyed web sites. However, currently no available tools or methods can prevent these attacks efficiently. By using Dynamic Information Flow Tracking (DIFT) techniques to track the flow of user credentials through the application´s language runtime, the model presented in this paper can automatically detect when an application safely and correctly authenticates users. Then the model combines authentication information with programmer-supplied access control rules to automatically ensure that only properly authenticated users are granted access to privileged resources or data.
Keywords :
Internet; Web sites; authorisation; DIFT techniques; Web application; Web bypass vulnerability prevention; Web sites; access control vulnerability; authentication attacks; dynamic information flow tracking techniques; programmer-supplied access control rules; unauthorized access; user authentication; user credentials; Authentication; Authorization; Databases; Operating systems; Runtime; bypass vulnerabilities; credentials tracking; web security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Electronic and Mechanical Engineering and Information Technology (EMEIT), 2011 International Conference on
Conference_Location :
Harbin, Heilongjiang, China
Print_ISBN :
978-1-61284-087-1
Type :
conf
DOI :
10.1109/EMEIT.2011.6023568
Filename :
6023568
Link To Document :
بازگشت