Towards stateless, client-side driven cross-site request forgery protection for web applications
Zusammenfassung
Cross-site request forgery (CSRF) is one of the dominant threats in the Web application landscape. In this paper, we present a lightweight and stateless protection mechanism that can be added to an existing application without requiring changes to the application's code. The key functionality of the approach, which is based on the double-submit technique, is purely implemented on the client-side. This way full coverage of client-side generation of HTTP requests is provided.
- Vollständige Referenz
- BibTeX
Lekies, S., Tighzert, W. & Johns, M.,
(2012).
Towards stateless, client-side driven cross-site request forgery protection for web applications.
In:
Suri, N. & Waidner, M.
(Hrsg.),
SICHERHEIT 2012 – Sicherheit, Schutz und Zuverlässigkeit.
Bonn:
Gesellschaft für Informatik e.V..
(S. 111-121).
@inproceedings{mci/Lekies2012,
author = {Lekies, Sebastian AND Tighzert, Walter AND Johns, Martin},
title = {Towards stateless, client-side driven cross-site request forgery protection for web applications},
booktitle = {SICHERHEIT 2012 – Sicherheit, Schutz und Zuverlässigkeit},
year = {2012},
editor = {Suri, Neeraj AND Waidner, Michael} ,
pages = { 111-121 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Lekies, Sebastian AND Tighzert, Walter AND Johns, Martin},
title = {Towards stateless, client-side driven cross-site request forgery protection for web applications},
booktitle = {SICHERHEIT 2012 – Sicherheit, Schutz und Zuverlässigkeit},
year = {2012},
editor = {Suri, Neeraj AND Waidner, Michael} ,
pages = { 111-121 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 978-3-88579-289-5
ISSN: 1617-5468
Datum: 2012
Sprache:
(en)
(en)
Typ: Text/Conference Paper

