{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T14:18:59Z","timestamp":1742912339923,"version":"3.40.3"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319388977"},{"type":"electronic","value":"9783319388984"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-38898-4_13","type":"book-chapter","created":{"date-parts":[[2016,5,6]],"date-time":"2016-05-06T07:44:40Z","timestamp":1462520680000},"page":"209-226","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["An Approach for Mitigating Potential Threats in Practical SSO Systems"],"prefix":"10.1007","author":[{"given":"Menghao","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liang","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zimu","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Xue","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,5,7]]},"reference":[{"key":"13_CR1","unstructured":"Juraj, S., Andreas, M., J\u00f6rg, S., Marco, K., Meiko, J.: On breaking SAML: be whoever you want to be. In: USENIX Security (2012)"},{"key":"13_CR2","unstructured":"Bai, G., Lei, J., Meng, G., Venkatraman, S.S., Saxena, P., Sun, J., Liu, Y., Dong, J.S.: AUTHSCAN: automatic extraction of web authentication protocols from implementations. In: NDSS (2013)"},{"key":"13_CR3","doi-asserted-by":"crossref","unstructured":"Wang, R., Chen, S., Wang, X.: Signing me onto your accounts through facebook and google: a traffic-guided security study of commercially deployed. In: IEEE S&P (2012)","DOI":"10.1109\/SP.2012.30"},{"key":"13_CR4","unstructured":"OpenID. \n                      http:\/\/openid.net\/"},{"key":"13_CR5","unstructured":"OAuth Protocols. \n                      http:\/\/oauth.net\/"},{"key":"13_CR6","unstructured":"Technology report SAML protocol. \n                      http:\/\/xml.coverpages.org\/saml.html"},{"key":"13_CR7","unstructured":"SAML2.0 Wikipedia. \n                      http:\/\/en.wikipedia.org\/wiki\/SAML\n                      \n                     2.0"},{"key":"13_CR8","doi-asserted-by":"crossref","unstructured":"Wang, R., Chen, S., Wang, X., Qadeer, S.: How to shop for free online security analysis of cashier-as-a-service based web stores. In: IEEE S&P (2011)","DOI":"10.1109\/SP.2011.26"},{"key":"13_CR9","unstructured":"Fiddler\u2013The free web debugging proxy. \n                      http:\/\/www.telerik.com\/fiddler"},{"key":"13_CR10","doi-asserted-by":"crossref","unstructured":"Armando, A., Carbone, R., Compagna, L., Cuellar, J., Abad, L.: Formal analysis of SAML 2.0 web browser single sign-on: breaking the SAML-based single sign-on for google apps. In: ACM FMSE (2008)","DOI":"10.1145\/1456396.1456397"},{"key":"13_CR11","unstructured":"OAuth2.0 Authorization Framework. \n                      http:\/\/tools.ietf.org\/html\/rfc6749"},{"key":"13_CR12","unstructured":"Google Accounts Authentication and Authorization. \n                      https:\/\/developers.google.com\/accounts\/docs\/OAuth2"},{"key":"13_CR13","unstructured":"OAuth2.0 documentation. \n                      http:\/\/oauth.net\/documentation\/"},{"key":"13_CR14","unstructured":"Wikipedia Tencent. \n                      http:\/\/en.wikipedia.org\/wiki\/Tencent"},{"key":"13_CR15","doi-asserted-by":"crossref","unstructured":"Bansal, C., Bhargavan, K., Maffeis, S.: Discovering concrete attacks on website authorization by formal analysis. In: IEEE CSF (2012)","DOI":"10.1109\/CSF.2012.27"},{"key":"13_CR16","unstructured":"Covert Redirect. \n                      http:\/\/tetraph.com\/covert_redirect\/"},{"key":"13_CR17","unstructured":"AlipayOpenAPI. \n                      https:\/\/openhome.alipay.com\/doc\/docIndex.htm"},{"key":"13_CR18","unstructured":"Google Accounts authorization and authentication Open ID 2.0 migration. \n                      https:\/\/developers.google.com\/accounts\/docs\/OpenID?hl=en-US"},{"key":"13_CR19","unstructured":"Google Accounts authorization and authentication Using OAuth2.0 for login (OpenID Connect). \n                      https:\/\/developers.google.com\/accounts\/docs\/OAuth2Login?hl=en-US"},{"key":"13_CR20","unstructured":"Google AuthSub. \n                      https:\/\/developers.google.com\/accounts\/docs\/AuthSub"},{"key":"13_CR21","doi-asserted-by":"crossref","unstructured":"Akhawe, D., Barth, A., Lam, P.E., Mitchell, J., Song, D.: Towards a formal foundation of web security. In: CSF (2010)","DOI":"10.1109\/CSF.2010.27"},{"key":"13_CR22","unstructured":"Sinaweibo, Wikipedia. \n                      http:\/\/en.wikipedia.org\/wiki\/SinaWeibo"},{"key":"13_CR23","unstructured":"Smartsheet.com, one online project management software. \n                      https:\/\/www.smartsheet.com\/"},{"key":"13_CR24","unstructured":"Weibo openAPI. \n                      http:\/\/open.weibo.com\/wiki\/"},{"key":"13_CR25","unstructured":"Covert Redirect Vulnerability Related to OAuth 2.0 and OpenID. \n                      http:\/\/tetraph.com\/covert_redirect\/oauth2_openid_covert_redirect.html"},{"key":"13_CR26","unstructured":"Taobao, Wikipedia. \n                      http:\/\/en.wikipedia.org\/wiki\/Taobao"},{"key":"13_CR27","unstructured":"AlipayWikipedia. \n                      http:\/\/en.wikipedia.org\/wiki\/Alibaba_Groupn#Alipay"},{"key":"13_CR28","unstructured":"Cross-Site Request Forgery (CSRF), The Open Web Application Security Project (OWASP). \n                      https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)"},{"key":"13_CR29","doi-asserted-by":"crossref","unstructured":"Sun, S.T., Beznosov. K.: The devil is in the (implementation) details: an empirical analysis of OAuth SSO systems. In: ACM CCS (2012)","DOI":"10.1145\/2382196.2382238"},{"key":"13_CR30","unstructured":"Cross-Site Scripting (XSS), The Open Web Application Security Project (OWASP). \n                      https:\/\/www.owasp.org\/index.php\/XSS"},{"key":"13_CR31","unstructured":"HttpOnly, The Open Web Application Security Project (OWASP). \n                      https:\/\/www.owasp.org\/index.php\/HttpOnly"},{"key":"13_CR32","unstructured":"Same Origin Policy, W3C Web Security. \n                      https:\/\/www.w3.org\/Security\/wiki\/Same_Origin_Policy"},{"key":"13_CR33","unstructured":"MitmProxy, An interactive console program that allows traffic flows to be intercepted, inspected, modified and replayed. \n                      https:\/\/mitmproxy.org\/"},{"key":"13_CR34","unstructured":"SSL Man in the Middle Proxy. \n                      http:\/\/crypto.stanford.edu\/ssl-mitm\/"},{"key":"13_CR35","unstructured":"Cloudshark Appliance. \n                      https:\/\/appliance.cloudshark.org\/"},{"key":"13_CR36","unstructured":"SSLsplit - transparent and scalable SSL\/TLS interception. \n                      https:\/\/www.roe.ch\/SSLsplit"},{"key":"13_CR37","unstructured":"Sslsniff, A tool for automated MITM attacks on SSL connections. \n                      http:\/\/www.thoughtcrime.org\/software\/sslsniff\/"},{"key":"13_CR38","unstructured":"Baidu, Wikipedia. \n                      http:\/\/en.wikipedia.org\/wiki\/Baidu"},{"key":"13_CR39","unstructured":"Zhou, Y., Evans, D.: SSOScan: automates testing of web applications for single sign on vulnerabilities. In: 23rd USENIX Security Symposium (2014)"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-38898-4_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T23:13:30Z","timestamp":1559430810000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-38898-4_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319388977","9783319388984"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-38898-4_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]},"assertion":[{"value":"7 May 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}