• DocumentCode
    568998
  • Title

    Automated detection of session management vulnerabilities in web applications

  • Author

    Takamatsu, Yusuke ; Kosuga, Yuji ; Kono, Kenji

  • Author_Institution
    Dept. of Inf. & Comput. Sci., Keio Univ., Yokohama, Japan
  • fYear
    2012
  • fDate
    16-18 July 2012
  • Firstpage
    112
  • Lastpage
    119
  • Abstract
    Many web applications employ session management to keep track of visitors´ activities across pages and over periods of time. A session is a period of time linked to a visitor, which is initiated when he/she arrives at a web application and it ends when his/her browser is closed or after a certain time of inactivity. Attackers can hijack a user´s session by exploiting session management vulnerabilities by means of session fixation and cross-site request forgery attacks. Even though such session management vulnerabilities can be eliminated in the development phase of web applications, the test operator is required to have detailed knowledge on the attacks and to set up a test environment each time he/she attempts to detect vulnerabilities. We propose a technique that automatically detects session management vulnerabilities in web applications by simulating real attacks. Our technique requires the test operator to only enter a few pieces of basic information about the web application, without requiring a test environment to be set up or detailed knowledge on the web application. Our experiments demonstrated that our technique could detect vulnerabilities in five web applications deployed in the real world.
  • Keywords
    Internet; security of data; transport protocols; Web browser; attack simulation; automatic session management vulnerability detection; cross-site request forgery attacks; session fixation; test operator; user inactivity; visitor activity tracking; Browsers; Data mining; Electronic mail; Force; Forgery; Knowledge engineering; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Privacy, Security and Trust (PST), 2012 Tenth Annual International Conference on
  • Conference_Location
    Paris
  • Print_ISBN
    978-1-4673-2323-9
  • Electronic_ISBN
    978-1-4673-2325-3
  • Type

    conf

  • DOI
    10.1109/PST.2012.6297927
  • Filename
    6297927