Skip to main navigation Skip to search Skip to main content

SERENE: Self-reliant client-side protection against session fixation

  • Philippe De Ryck
  • , Nick Nikiforakis
  • , Lieven Desmet
  • , Frank Piessens
  • , Wouter Joosen
  • KU Leuven

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

18 Scopus citations

Abstract

The web is the most wide-spread and de facto distributed platform, with a plethora of valuable applications and services. Building stateful services on the web requires a session mechanism that keeps track of server-side session state, such as authentication data. These sessions are an attractive attacker target, since taking over an authenticated session fully compromises the user's account. This paper focuses on session fixation, where an attacker forces the user to use the attacker's session, allowing the attacker to take over the session after authentication. We present Serene, a self-reliant client-side countermeasure that protects the user from session fixation attacks, regardless of the security provisions - or lack thereof - of a web application. By specifically protecting session identifiers from fixation and not interfering with other cookies or parameters, Serene is able to autonomously protect a large majority of web applications, without being disruptive towards legitimate functionality. We experimentally validate these claims with a large scale study of Alexa's top one million sites, illustrating both Serene's large coverage (83.43%) and compatibility (95.55%).

Original languageEnglish
Title of host publicationDistributed Applications and Interoperable Systems - 12th IFIP WG 6.1 International Conference, DAIS 2012, Proceedings
Pages59-72
Number of pages14
DOIs
StatePublished - 2012
Event12th IFIP International Conference on Distributed Applications and Interoperable Systems, DAIS 2012 - Stockholm, Sweden
Duration: Jun 13 2012Jun 16 2012

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7272 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference12th IFIP International Conference on Distributed Applications and Interoperable Systems, DAIS 2012
Country/TerritorySweden
CityStockholm
Period06/13/1206/16/12

Keywords

  • security
  • session fixation
  • web applications

Fingerprint

Dive into the research topics of 'SERENE: Self-reliant client-side protection against session fixation'. Together they form a unique fingerprint.

Cite this