DocumentCode
154039
Title
Provably Sound Browser-Based Enforcement of Web Session Integrity
Author
Bugliesi, Michele ; Calzavara, Stefano ; Focardi, Riccardo ; Khan, Wilayat ; Tempesta, Mauro
fYear
2014
fDate
19-22 July 2014
Firstpage
366
Lastpage
380
Abstract
Enforcing protection at the browser side has recently become a popular approach for securing web authentication. Though interesting, existing attempts in the literature only address specific classes of attacks, and thus fall short of providing robust foundations to reason on web authentication security. In this paper we provide such foundations, by introducing a novel notion of web session integrity, which allows us to capture many existing attacks and spot some new ones. We then propose FF+, a security-enhanced model of a web browser that provides a full-fledged and provably sound enforcement of web session integrity. We leverage our theory to develop Sess Int, a prototype extension for Google Chrome implementing the security mechanisms formalized in FF+. Sess Int provides a level of security very close to FF+, while keeping an eye at usability and user experience.
Keywords
authorisation; online front-ends; FF+; Google Chrome; Web authentication security; Web session integrity; a security-enhanced model; browser side protection; provably sound browser-based enforcement; Authentication; Browsers; Proposals; Protocols; Robustness; Servers;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Security Foundations Symposium (CSF), 2014 IEEE 27th
Conference_Location
Vienna
Type
conf
DOI
10.1109/CSF.2014.33
Filename
6957123
Link To Document