DocumentCode
554613
Title
A conceptual model for preventing web bypass vulnerabilities
Author
Zhiqiang Wei ; Kaiyuan Shi ; Dongning Jia
Author_Institution
Dept. of Comput. Sci., Ocean Univ. of China, Qingdao, China
Volume
5
fYear
2011
fDate
12-14 Aug. 2011
Firstpage
2287
Lastpage
2290
Abstract
This paper provides a conceptual model for reducing bypass vulnerabilities in web applications. The typical and primary two kinds of bypass vulnerabilities are authentication and access control vulnerabilities. Authentication attacks occur when a web application authenticates users incorrectly and grants access for users without appropriate credentials. Access control attacks happen when access control check is incorrect or missing, allowing unauthorized access to privileged resources. Such attacks are getting increasingly common and have occurred in many famous web applications such as IIS and WordPress, and 14% of surveyed web sites. However, currently no available tools or methods can prevent these attacks efficiently. By using Dynamic Information Flow Tracking (DIFT) techniques to track the flow of user credentials through the application´s language runtime, the model presented in this paper can automatically detect when an application safely and correctly authenticates users. Then the model combines authentication information with programmer-supplied access control rules to automatically ensure that only properly authenticated users are granted access to privileged resources or data.
Keywords
Internet; Web sites; authorisation; DIFT techniques; Web application; Web bypass vulnerability prevention; Web sites; access control vulnerability; authentication attacks; dynamic information flow tracking techniques; programmer-supplied access control rules; unauthorized access; user authentication; user credentials; Authentication; Authorization; Databases; Operating systems; Runtime; bypass vulnerabilities; credentials tracking; web security;
fLanguage
English
Publisher
ieee
Conference_Titel
Electronic and Mechanical Engineering and Information Technology (EMEIT), 2011 International Conference on
Conference_Location
Harbin, Heilongjiang, China
Print_ISBN
978-1-61284-087-1
Type
conf
DOI
10.1109/EMEIT.2011.6023568
Filename
6023568
Link To Document