Скачать презентацию Cross-Site-Request-Forgery Optimizing Traditional and Advocating New Prevention Methods Скачать презентацию Cross-Site-Request-Forgery Optimizing Traditional and Advocating New Prevention Methods

c0126aa09708cdd9acf6e7070b7166ca.ppt

  • Количество слайдов: 14

Cross-Site-Request-Forgery Optimizing Traditional and Advocating New Prevention Methods Mark Jenne Tatiana Alexenko Cross-Site-Request-Forgery Optimizing Traditional and Advocating New Prevention Methods Mark Jenne Tatiana Alexenko

CSRF Overview Forces user to send unauthorized requests by interacting with a malicious website. CSRF Overview Forces user to send unauthorized requests by interacting with a malicious website. The “sleeping giant” of all cyber security threats. Can force someone to transfer money, change status on social networking site, buy stock, or any other action on a vulnerable website an attacker would like to exploit.

CSRF Overview CSRF Overview

Original Project Plan Week 2: Reading and Preparation Weeks 3 -4: Perform Simple CSRF Original Project Plan Week 2: Reading and Preparation Weeks 3 -4: Perform Simple CSRF Attacks Develop testbed and exploit generated site Weeks 5 -7: Implement Defense Mechanisms Gain a better understanding of csrf attack mechanisms Referrer-checking, reconfirmation, any others Weeks 8 -9: Final Preparation Finalize project, conference paper, presentation

Alterations to the Plan Reconfirmation protection method Recon value to be based of off Alterations to the Plan Reconfirmation protection method Recon value to be based of off the trace path Trace path would not work since it would just go back to the user's browser. Would be unable to compare trace path of user and attack since both would lead to same machine. CCNC Conference Decided to submit paper to CCNC instead of ACM hotnets. Social Networking specification – had to find exploits in well-known social networks to present.

Test Bed Application Stock trading application Registered users can buy and sell stock based Test Bed Application Stock trading application Registered users can buy and sell stock based on prices from Yahoo Finance. Utilizes an AJAX request to retrieve stock information in real time Does not implement any CSRF protection methods – allowed us to concentrate on CSRF without the presence of XSS.

Test Bed Application Test Bed Application

Sample Attack <iframe src = Sample Attack