Skip to main navigation Skip to search Skip to main content

SessionShield: Lightweight protection against session hijacking

  • KU Leuven
  • SAP Research

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

57 Scopus citations

Abstract

The class of Cross-site Scripting (XSS) vulnerabilities is the most prevalent security problem in the field of Web applications. One of the main attack vectors used in connection with XSS is session hijacking via session identifier theft. While session hijacking is a client-side attack, the actual vulnerability resides on the server-side and, thus, has to be handled by the website's operator. In consequence, if the operator fails to address XSS, the application's users are defenseless against session hijacking attacks. In this paper we present SessionShield, a lightweight client-side protection mechanism against session hijacking that allows users to protect themselves even if a vulnerable website's operator neglects to mitigate existing XSS problems. SessionShield is based on the observation that session identifier values are not used by legitimate client-side scripts and, thus, need not to be available to the scripting languages running in the browser. Our system requires no training period and imposes negligible overhead to the browser, therefore, making it ideal for desktop and mobile systems.

Original languageEnglish
Title of host publicationEngineering Secure Software and Systems - Third International Symposium, ESSoS 2011, Proceedings
Pages87-100
Number of pages14
DOIs
StatePublished - 2011
Event3rd International Symposium on Engineering Secure Software and Systems, ESSoS 2011 - Madrid, Spain
Duration: Feb 9 2011Feb 10 2011

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume6542 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference3rd International Symposium on Engineering Secure Software and Systems, ESSoS 2011
Country/TerritorySpain
CityMadrid
Period02/9/1102/10/11

Keywords

  • client-side proxy
  • http-only
  • session hijacking

Fingerprint

Dive into the research topics of 'SessionShield: Lightweight protection against session hijacking'. Together they form a unique fingerprint.

Cite this