White Papers

Robust Defenses for Cross-Site Request Forgery

Category: Security

Overview Cross-Site Request Forgery (CSRF) is a widely exploited web site vulnerability. This paper presents a new variation on CSRF attacks, login CSRF, in which the attacker forges a cross-site request to the login form, logging the victim into the honest web site as the attacker. The severity of login CSRF vulnerability varies by site, but it can be as severe as a cross-site scripting vulnerability. It detailed three major CSRF defense techniques and find shortcomings with each technique. Its observations do suggest, however, that the header can be used today as a reliable CSRF defense over HTTPS, making it particularly well-suited for defending against login CSRF. It also proposes that browsers implement the Origin header, which provides the security benefits of the Referer header while responding to privacy concerns.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Association for Computing Machinery
File Format
PDF
Date Published
Jun 30, 2009
Format
White Papers
Topics
Network Security, Security Management

Similiar White Papers

Use these Registry settings to help lock down Windows

Use these Registry settings to help lock down Windows

This sample chapter, taken from Microsoft Windows Registry Guide, Second Edition discusses how to use the registr

Publisher: TechRepublic  |  Tags: microsoft windows, network, windows server, windows xp, xp

Anonymous Proxy: A Growing Trend in Internet Abuse

Anonymous Proxy: A Growing Trend in Internet Abuse

Anonymous proxies are an unseen threat--a student's or employee's backdoor to malicious or productivity-sapping sites on

Publisher: Bloxx  |  Tags: database, third-generation, trend

Tivoli WebSEAL - Sizing and Capacity Planning

Tivoli WebSEAL - Sizing and Capacity Planning

WebSEAL is a component of Tivoli Access Manager for e-business that provides an authentication and authorization mechani

Publisher: IBM  |  Tags: authentication, network, os, password, server

Balancing Security Against Productivity

Balancing Security Against Productivity

What makes for great security? Is it about keeping the bad guys out or letting the good guys in? About defending atta

Publisher: Novell  |  Tags: management, security management

A Brief History of Network Security and the Need for Host Based Intrusion Detection

A Brief History of Network Security and the Need for Host Based Intrusion Detection

This paper describes the present state of information and network security with specific concentration on Host-based Int

Publisher: Tetrad Digital Integrity (TDI)  |  Tags: network, network security

Association for Computing Machinery White Papers

Managing ETL Processes

Managing ETL Processes

ETL tools allow the definition of sometimes complex processes to extract, transform, and load heterogeneous data into a

Publisher: Association for Computing Machinery  |  Tags: data, data integration, data warehouse, management

GPS-Free Node Localization in Mobile Wireless Sensor Networks

GPS-Free Node Localization in Mobile Wireless Sensor Networks

An important problem in mobile ad-hoc wireless sensor networks is the localization of individual nodes, i.e., each node'

Publisher: Association for Computing Machinery  |  Tags: gps, infrastructure, network

A Black-Box Approach for Web Application SLA

A Black-Box Approach for Web Application SLA

Web servers nowadays have to cope with unprecedented amounts of workload, due to increasing popularity and complexity; i

Publisher: Association for Computing Machinery  |  Tags: applications, server

Load Balancing for Multimedia Streaming in Heterogeneous Peer-to-Peer Systems

Load Balancing for Multimedia Streaming in Heterogeneous Peer-to-Peer Systems

Multimedia streaming of mostly user generated content is an ongoing trend, not only since the upcoming of Last.fm and Yo

Publisher: Association for Computing Machinery  |  Tags: user generated, user generated content, youtube

Multiobjective Network Design for Realistic Traffic Models

Multiobjective Network Design for Realistic Traffic Models

Network topology design problems find application in several real life scenarios. However, most designs in the past eith

Publisher: Association for Computing Machinery  |  Tags: network, realistic