• DocumentCode
    154039
  • Title

    Provably Sound Browser-Based Enforcement of Web Session Integrity

  • Author

    Bugliesi, Michele ; Calzavara, Stefano ; Focardi, Riccardo ; Khan, Wilayat ; Tempesta, Mauro

  • fYear
    2014
  • fDate
    19-22 July 2014
  • Firstpage
    366
  • Lastpage
    380
  • Abstract
    Enforcing protection at the browser side has recently become a popular approach for securing web authentication. Though interesting, existing attempts in the literature only address specific classes of attacks, and thus fall short of providing robust foundations to reason on web authentication security. In this paper we provide such foundations, by introducing a novel notion of web session integrity, which allows us to capture many existing attacks and spot some new ones. We then propose FF+, a security-enhanced model of a web browser that provides a full-fledged and provably sound enforcement of web session integrity. We leverage our theory to develop Sess Int, a prototype extension for Google Chrome implementing the security mechanisms formalized in FF+. Sess Int provides a level of security very close to FF+, while keeping an eye at usability and user experience.
  • Keywords
    authorisation; online front-ends; FF+; Google Chrome; Web authentication security; Web session integrity; a security-enhanced model; browser side protection; provably sound browser-based enforcement; Authentication; Browsers; Proposals; Protocols; Robustness; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Foundations Symposium (CSF), 2014 IEEE 27th
  • Conference_Location
    Vienna
  • Type

    conf

  • DOI
    10.1109/CSF.2014.33
  • Filename
    6957123