完整後設資料紀錄
DC 欄位語言
dc.contributor.authorSung, Yin-Changen_US
dc.contributor.authorCho, Michael Cheng Yien_US
dc.contributor.authorWang, Chi-Weien_US
dc.contributor.authorHsu, Chia-Weien_US
dc.contributor.authorShieh, Shiuhpyng Winstonen_US
dc.date.accessioned2014-12-08T15:33:12Z-
dc.date.available2014-12-08T15:33:12Z-
dc.date.issued2013en_US
dc.identifier.isbn978-0-7695-5021-3en_US
dc.identifier.urihttp://hdl.handle.net/11536/23078-
dc.identifier.urihttp://dx.doi.org/10.1109/SERE.2013.22en_US
dc.description.abstractCross-site request forgery (CSRF/XSRF) is a serious vulnerability in Web 2.0 environment. With CSRF, an adversary can spoof the payload of an HTTP request and entice the victim's browser to transmit an HTTP request to the web server. Consequently, the server cannot determine legitimacy of the HTTP request. This paper presents a light-weight CSRF prevention method by introducing a quarantine system to inspect suspicious scripts on the server-side. Instead of using script filtering and rewriting approach, this scheme is based on a new labeling mechanism (we called it Content Box) which enables the web server to distinguish the malicious requests from the harmless requests without the need to modify the user created contents (UCCs). Consequently, a malicious request can be blocked when it attempts to access critical web services that was defined by the web administrator. To demonstrate the effectiveness of the proposed scheme, the proposed scheme was implemented and the performance was evaluated.en_US
dc.language.isoen_USen_US
dc.subjectcross-site request forgeryen_US
dc.subjectlight-weighten_US
dc.subjectWeb 2.0en_US
dc.subjectuser-created contentsen_US
dc.titleLight-Weight CSRF Protection by Labeling User-Created Contentsen_US
dc.typeProceedings Paperen_US
dc.identifier.doi10.1109/SERE.2013.22en_US
dc.identifier.journal2013 IEEE 7TH INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY (SERE)en_US
dc.citation.spage60en_US
dc.citation.epage69en_US
dc.contributor.department資訊工程學系zh_TW
dc.contributor.departmentDepartment of Computer Scienceen_US
dc.identifier.wosnumberWOS:000327102200012-
顯示於類別:會議論文


文件中的檔案:

  1. 000327102200012.pdf

若為 zip 檔案,請下載檔案解壓縮後,用瀏覽器開啟資料夾中的 index.html 瀏覽全文。