Skip to main navigation Skip to search Skip to main content

DEMACRO: Defense against malicious cross-domain requests

  • Sebastian Lekies
  • , Nick Nikiforakis
  • , Walter Tighzert
  • , Frank Piessens
  • , Martin Johns
  • SAP Research
  • KU Leuven

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

In the constant evolution of theWeb, the simple always gives way to the more complex. Static webpages with click-through dialogues are becoming more and more obsolete and in their place, asynchronous JavaScript requests, Web mash-ups and proprietary plug-ins with the ability to conduct cross-domain requests shape the modern user experience. Three recent studies showed that a significant number ofWeb applications implement poor cross-domain policies allowing malicious domains to embed Flash and Silverlight applets which can conduct arbitrary requests to these Web applications under the identity of the visiting user. In this paper, we confirm the findings of the aforementioned studies and we design DEMACRO, a client-side defense mechanism which detects potentially malicious cross-domain requests and de-authenticates them by removing existing session credentials. Our system requires no training or user interaction and imposes minimal performance overhead on the user's browser.

Original languageEnglish
Title of host publicationResearch in Attacks, Intrusions, and Defenses - 15th International Symposium, RAID 2012, Proceedings
PublisherSpringer Verlag
Pages254-273
Number of pages20
ISBN (Print)9783642333378
DOIs
StatePublished - 2012
Event15th International Symposium on Research in Attacks, Intrusions, and Defenses, RAID 2012 - Amsterdam, Netherlands
Duration: Sep 12 2012Sep 14 2012

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7462 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference15th International Symposium on Research in Attacks, Intrusions, and Defenses, RAID 2012
Country/TerritoryNetherlands
CityAmsterdam
Period09/12/1209/14/12

Fingerprint

Dive into the research topics of 'DEMACRO: Defense against malicious cross-domain requests'. Together they form a unique fingerprint.

Cite this