{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T23:49:01Z","timestamp":1725925741795},"publisher-location":"Cham","reference-count":49,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319725970"},{"type":"electronic","value":"9783319725987"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-72598-7_16","type":"book-chapter","created":{"date-parts":[[2017,12,1]],"date-time":"2017-12-01T12:06:49Z","timestamp":1512130009000},"page":"263-282","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Modelling and Mitigation of Cross-Origin Request Attacks on Federated Identity Management Using Cross Origin Request Policy"],"prefix":"10.1007","author":[{"given":"Akash","family":"Agrawall","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shubh","family":"Maheshwari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Projit","family":"Bandyopadhyay","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Venkatesh","family":"Choppella","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,12,2]]},"reference":[{"key":"16_CR1","unstructured":"Cross-Site Request Forgery (CSRF). https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)"},{"key":"16_CR2","unstructured":"Cybercrime time-line. http:\/\/www.symantec.com\/region\/sg\/homecomputing\/library\/cybercrime.html"},{"key":"16_CR3","unstructured":"Modify headers for Google Chrome. https:\/\/chrome.google.com\/webstore\/detail\/modify-headers-for-google\/innpjfdalfhpcoinfnehdnbkglpmogdi"},{"key":"16_CR4","unstructured":"OWASP top 10 application security risks - 2017. https:\/\/www.owasp.org\/index.php\/Top_10_2017-Top_10"},{"key":"16_CR5","unstructured":"ProfileJacking - legal tricks to detect user profile. Blog, https:\/\/sakurity.com\/blog\/2015\/03\/10\/Profilejacking.html"},{"key":"16_CR6","unstructured":"Rivery crossing. http:\/\/alloy.mit.edu\/alloy\/tutorials\/online\/frame-RC-1.html"},{"key":"16_CR7","unstructured":"Same site cookie. https:\/\/www.owasp.org\/index.php\/SameSite"},{"key":"16_CR8","unstructured":"Security assertion markup language. Article, https:\/\/en.wikipedia.org\/wiki\/Security_Assertion_Markup_Language"},{"key":"16_CR9","unstructured":"User logout is vulnerable to CSRF. https:\/\/www.drupal.org\/node\/144538"},{"key":"16_CR10","unstructured":"XSRF in the logout handler. https:\/\/sites.google.com\/site\/bughunteruniversity\/nonvuln\/logout-xsrf"},{"key":"16_CR11","unstructured":"Yii 1.1: Logout CSRF protection. http:\/\/www.yiiframework.com\/wiki\/190\/logout-csrf-protection\/"},{"key":"16_CR12","unstructured":"Your social media fingerprint. https:\/\/robinlinus.github.io\/socialmedia-leak\/"},{"key":"16_CR13","unstructured":"Federated SSO primer, April 2015. https:\/\/developer.pingidentity.com\/en\/resources\/federated-sso-overview.html"},{"key":"16_CR14","unstructured":"Login\/logout CSRF: Time to reconsider? Article, March 2017, https:\/\/labs.detectify.com\/2017\/03\/15\/loginlogout-csrf-time-to-reconsider\/"},{"key":"16_CR15","doi-asserted-by":"crossref","unstructured":"Agrawall, A., Chaitanya, K., Agrawal, A.K., Choppella, V.: Mitigating browser-based DDoS attacks using CORP. In: Proceedings of the 10th Innovations in Software Engineering Conference, pp. 137\u2013146. ACM (2017)","DOI":"10.1145\/3021460.3021477"},{"key":"16_CR16","unstructured":"Elsobky, A.: Novel techniques for user deanonymization attacks. https:\/\/0xsobky.github.io\/novel-deanonymization-techniques\/"},{"key":"16_CR17","doi-asserted-by":"crossref","unstructured":"Akhawe, D., Barth, A., Lam, P.E., Mitchell, J., Song, D.: Towards a formal foundation of web security. In: 2010 23rd IEEE Computer Security Foundations Symposium (CSF), pp. 290\u2013304. IEEE (2010)","DOI":"10.1109\/CSF.2010.27"},{"key":"16_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1007\/11513988_27","volume-title":"Computer Aided Verification","author":"A Armando","year":"2005","unstructured":"Armando, A., Basin, D., Boichut, Y., Chevalier, Y., Compagna, L., Cuellar, J., Drielsma, P.H., He\u00e1m, P.C., Kouchnarenko, O., Mantovani, J., M\u00f6dersheim, S., von Oheimb, D., Rusinowitch, M., Santiago, J., Turuani, M., Vigan\u00f2, L., Vigneron, L.: The AVISPA tool for the automated validation of internet security protocols and applications. In: Etessami, K., Rajamani, S.K. (eds.) CAV 2005. LNCS, vol. 3576, pp. 281\u2013285. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11513988_27"},{"key":"16_CR19","doi-asserted-by":"crossref","unstructured":"Armando, A., Carbone, R., Compagna, L., Cuellar, J., Tobarra, L.: Formal analysis of SAML 2.0 web browser single sign-on: breaking the SAML-based single sign-on for Google apps. In: Proceedings of the 6th ACM Workshop on Formal Methods in Security Engineering, pp. 1\u201310. ACM (2008)","DOI":"10.1145\/1456396.1456397"},{"key":"16_CR20","doi-asserted-by":"crossref","unstructured":"Barth, A., Jackson, C., Mitchell, J.C.: Robust defenses for cross-site request forgery. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 75\u201388. ACM (2008)","DOI":"10.1145\/1455770.1455782"},{"key":"16_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1007\/11841197_6","volume-title":"Web Services and Formal Methods","author":"K Bhargavan","year":"2006","unstructured":"Bhargavan, K., Fournet, C., Gordon, A.D.: Verified reference implementations of WS-security protocols. In: Bravetti, M., N\u00fa\u00f1ez, M., Zavattaro, G. (eds.) WS-FM 2006. LNCS, vol. 4184, pp. 88\u2013106. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11841197_6"},{"key":"16_CR22","doi-asserted-by":"crossref","unstructured":"Bortz, A., Boneh, D.: Exposing private information by timing web applications. In: Proceedings of the 16th international Conference on World Wide Web, pp. 621\u2013628. ACM (2007)","DOI":"10.1145\/1242572.1242656"},{"key":"16_CR23","doi-asserted-by":"crossref","unstructured":"Cao, Y., Rastogi, V., Li, Z., Chen, Y., Moshchuk, A.: Redefining web browser principals with a configurable origin policy. In: 2013 43rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 1\u201312. IEEE (2013)","DOI":"10.1109\/DSN.2013.6575317"},{"key":"16_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1007\/978-3-642-03829-7_3","volume-title":"Foundations of Security Analysis and Design V","author":"DW Chadwick","year":"2009","unstructured":"Chadwick, D.W.: Federated identity management. In: Aldini, A., Barthe, G., Gorrieri, R. (eds.) FOSAD 2007-2009. LNCS, vol. 5705, pp. 96\u2013120. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-03829-7_3"},{"key":"16_CR25","doi-asserted-by":"crossref","unstructured":"Chen, B., Zavarsky, P., Ruhl, R., Lindskog, D.: A study of the effectiveness of CSRF guard. In: 2011 IEEE Third International Conference on Privacy, Security, Risk and Trust (PASSAT) and 2011 IEEE Third Inernational Conference on Social Computing (SocialCom), pp. 1269\u20131272. IEEE (2011)","DOI":"10.1109\/PASSAT\/SocialCom.2011.58"},{"key":"16_CR26","doi-asserted-by":"crossref","unstructured":"Chen, E.Y., Bau, J., Reis, C., Barth, A., Jackson, C.: App isolation: get the security of multiple browsers with just one. In: Proceedings of the 18th ACM Conference on Computer and Communications Security, pp. 227\u2013238. ACM (2011)","DOI":"10.1145\/2046707.2046734"},{"issue":"8","key":"16_CR27","doi-asserted-by":"crossref","first-page":"953","DOI":"10.1016\/S0169-7552(97)00009-3","volume":"29","author":"Y-H Chu","year":"1997","unstructured":"Chu, Y.-H., Feigenbaum, J., LaMacchia, B., Resnick, P., Strauss, M.: REFEREE: trust management for web applications. Comput. Netw. ISDN Syst. 29(8), 953\u2013964 (1997)","journal-title":"Comput. Netw. ISDN Syst."},{"issue":"4","key":"16_CR28","doi-asserted-by":"crossref","first-page":"443","DOI":"10.1145\/363516.363528","volume":"9","author":"EM Clarke","year":"2000","unstructured":"Clarke, E.M., Jha, S., Marrero, W.: Verifying security protocols with Brutus. ACM Trans. Softw. Eng. Methodol. (TOSEM) 9(4), 443\u2013487 (2000)","journal-title":"ACM Trans. Softw. Eng. Methodol. (TOSEM)"},{"key":"16_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1007\/978-3-540-70545-1_38","volume-title":"Computer Aided Verification","author":"CJF Cremers","year":"2008","unstructured":"Cremers, C.J.F.: The Scyther tool: verification, falsification, and analysis of security protocols. In: Gupta, A., Malik, S. (eds.) CAV 2008. LNCS, vol. 5123, pp. 414\u2013418. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-70545-1_38"},{"key":"16_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"100","DOI":"10.1007\/978-3-642-23822-2_6","volume-title":"Computer Security \u2013 ESORICS 2011","author":"P Ryck De","year":"2011","unstructured":"De Ryck, P., Desmet, L., Joosen, W., Piessens, F.: Automatic and precise client-side protection against CSRF attacks. In: Atluri, V., Diaz, C. (eds.) ESORICS 2011. LNCS, vol. 6879, pp. 100\u2013116. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-23822-2_6"},{"key":"16_CR31","doi-asserted-by":"crossref","unstructured":"Dhamija, R., Tygar, J.D., Hearst, M.: Why phishing works. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, pp. 581\u2013590. ACM (2006)","DOI":"10.1145\/1124772.1124861"},{"issue":"3","key":"16_CR32","doi-asserted-by":"crossref","first-page":"277","DOI":"10.1007\/s00165-004-0058-1","volume":"17","author":"AD Gordon","year":"2005","unstructured":"Gordon, A.D., Pucella, R.: Validating a web service security abstraction by typing. Formal Aspects Comput. 17(3), 277\u2013318 (2005)","journal-title":"Formal Aspects Comput."},{"key":"16_CR33","doi-asserted-by":"crossref","unstructured":"Hardt, D.: The OAuth 2.0 authorization framework (2012)","DOI":"10.17487\/rfc6749"},{"key":"16_CR34","unstructured":"Grossman, J.: Login detection, whose problem is it? March 2008. http:\/\/blog.jeremiahgrossman.com\/2008\/03\/login-detection-whose-problem-is-it.html"},{"key":"16_CR35","unstructured":"Johns, M., Winter, J.: RequestRodeo: client side protection against session riding. In: Proceedings of the OWASP Europe 2006 Conference (2006)"},{"key":"16_CR36","first-page":"113","volume":"22","author":"K Krombholz","year":"2015","unstructured":"Krombholz, K., Hobel, H., Huber, M., Weippl, E.: Advanced social engineering attacks. J. Inf. Secur. Appl. 22, 113\u2013122 (2015)","journal-title":"J. Inf. Secur. Appl."},{"key":"16_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1007\/978-3-642-03549-4_15","volume-title":"Financial Cryptography and Data Security","author":"Z Mao","year":"2009","unstructured":"Mao, Z., Li, N., Molloy, I.: Defeating cross-site request forgery attacks with browser-enforced authenticity protection. In: Dingledine, R., Golle, P. (eds.) FC 2009. LNCS, vol. 5628, pp. 238\u2013255. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-03549-4_15"},{"key":"16_CR38","doi-asserted-by":"crossref","unstructured":"Oda, T., Wurster, G., van Oorschot, P.C., Somayaji, A.: SOMA: mutual approval for included content in web pages. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 89\u201398. ACM (2008)","DOI":"10.1145\/1455770.1455783"},{"key":"16_CR39","unstructured":"Wagenseil, P.: LastPass can be spoofed in devastating phishing attacks. Article, January 2016. www.tomsguide.com\/us\/lastpass-phishing-attacks,news-22139.html"},{"key":"16_CR40","doi-asserted-by":"crossref","unstructured":"Recordon, D., Reed, D.: OpenID 2.0: a platform for user-centric identity management. In: Proceedings of the Second ACM Workshop on Digital Identity Management, pp. 11\u201316. ACM (2006)","DOI":"10.1145\/1179529.1179532"},{"key":"16_CR41","unstructured":"Hansen, R., Grossman, J.: Clickjacking. Blog, December 2008, http:\/\/www.sectheory.com\/clickjacking.htm"},{"key":"16_CR42","unstructured":"Ruddy, M.: Decision point for federated identity and cross-domain single sign-on. Article, April 2015, https:\/\/www.gartner.com\/doc\/3029229\/decision-point-federated-identity-crossdomain"},{"key":"16_CR43","first-page":"1","volume":"1","author":"K Spett","year":"2005","unstructured":"Spett, K.: Cross-site scripting. SPI Labs 1, 1\u201320 (2005)","journal-title":"SPI Labs"},{"key":"16_CR44","unstructured":"Morgan, S.: Cyber crime costs projected to reach 2 trillion by 2019. Article, January 2016. https:\/\/www.forbes.com\/sites\/stevemorgan\/2016\/01\/17\/cyber-crime-costs-projected-to-reach-2-trillion-by-2019\/#3c5ecbfe3a91"},{"key":"16_CR45","doi-asserted-by":"publisher","unstructured":"Telikicherla, K.C., Agrawall, A., Choppella, V.: A formal model of web security showing malicious cross origin requests and its mitigation using CORP. In: Proceedings of the 3rd International Conference on Information Systems Security and Privacy, ICISSP 2017, Porto, Portugal, 19\u201321 February 2017, pp. 516\u2013523 (2017). https:\/\/doi.org\/10.5220\/0006261105160523","DOI":"10.5220\/0006261105160523"},{"key":"16_CR46","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"277","DOI":"10.1007\/978-3-319-13841-1_16","volume-title":"Information Systems Security","author":"KC Telikicherla","year":"2014","unstructured":"Telikicherla, K.C., Choppella, V., Bezawada, B.: CORP: a browser policy to mitigate web infiltration attacks. In: Prakash, A., Shyamasundar, R. (eds.) ICISS 2014. LNCS, vol. 8880, pp. 277\u2013297. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-13841-1_16"},{"key":"16_CR47","unstructured":"Tom, A.: Detect if visitors are logged into Twitter, Facebook or Google+, February 2012. http:\/\/www.tomanthony.co.uk\/blog\/detect-visitor-social-networks\/"},{"key":"16_CR48","unstructured":"W3C: History of the World Wide Web. Technical report (1989). http:\/\/www.w3.org\/Consortium\/facts#history"},{"key":"16_CR49","unstructured":"Zalewski, M.: Browser Security Handbook. Technical report (2011), https:\/\/code.google.com\/p\/browsersec\/wiki\/Part2#Same-origin_policy"}],"container-title":["Lecture Notes in Computer Science","Information Systems Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-72598-7_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,7]],"date-time":"2019-10-07T03:37:58Z","timestamp":1570419478000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-72598-7_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319725970","9783319725987"],"references-count":49,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-72598-7_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2017]]}}}