{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T06:21:31Z","timestamp":1725517291865},"publisher-location":"Berlin, Heidelberg","reference-count":22,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642322860"},{"type":"electronic","value":"9783642322877"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-32287-7_2","type":"book-chapter","created":{"date-parts":[[2012,8,20]],"date-time":"2012-08-20T02:35:41Z","timestamp":1345430141000},"page":"17-29","source":"Crossref","is-referenced-by-count":1,"title":["A User-Level Authentication Scheme to Mitigate Web Session-Based Vulnerabilities"],"prefix":"10.1007","author":[{"given":"Bastian","family":"Braun","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefan","family":"Kucher","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Johns","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Joachim","family":"Posegga","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"2_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"294","DOI":"10.1007\/3-540-39200-9_18","volume-title":"Advances in Cryptology \u2013 EUROCRPYT 2003","author":"L. Ahn Von","year":"2003","unstructured":"Von Ahn, L., Blum, M., Hopper, N.J., Langford, J.: CAPTCHA: Using Hard AI Problems for Security. In: Biham, E. (ed.) EUROCRYPT 2003. LNCS, vol.\u00a02656, pp. 294\u2013311. Springer, Heidelberg (2003)"},{"key":"2_CR2","doi-asserted-by":"crossref","unstructured":"Barth, A., Jackson, C., Mitchell, J.C.: Robust Defenses for Cross-Site Request Forgery. In: CCS 2009 (2009)","DOI":"10.1145\/1455770.1455782"},{"key":"2_CR3","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1145\/54289.871709","volume":"22","author":"N. Hardy","year":"1988","unstructured":"Hardy, N.: The Confused Deputy (or why capabilities might have been invented). SIGOPS Oper. Syst. Rev.\u00a022, 36\u201338 (1988)","journal-title":"SIGOPS Oper. Syst. Rev."},{"key":"2_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"444","DOI":"10.1007\/11863908_27","volume-title":"Computer Security \u2013 ESORICS 2006","author":"M. Johns","year":"2006","unstructured":"Johns, M.: SessionSafe: Implementing XSS Immune Session Handling. In: Gollmann, D., Meier, J., Sabelfeld, A. (eds.) ESORICS 2006. LNCS, vol.\u00a04189, pp. 444\u2013460. Springer, Heidelberg (2006)"},{"key":"2_CR5","doi-asserted-by":"crossref","unstructured":"Johns, M., Braun, B., Schrank, M., Posegga, J.: Reliable Protection Against Session Fixation Attacks. In: Proceedings of ACM SAC (2011)","DOI":"10.1145\/1982185.1982511"},{"key":"2_CR6","unstructured":"Johns, M., Winter, J.: RequestRodeo: Client Side Protection against Session Riding. In: OWASP Europe 2006 (May 2006)"},{"key":"2_CR7","doi-asserted-by":"crossref","unstructured":"Jovanovic, N., Kruegel, C., Kirda, E.: Preventing cross site request forgery attacks. In: Proceedings of Securecomm 2006 (2006)","DOI":"10.1109\/SECCOMW.2006.359531"},{"key":"2_CR8","unstructured":"Kolsek, M.: Session Fixation Vulnerability in Web-based Applications. Whitepaper, Acros Security (December 2002), \n                    \n                      http:\/\/www.acrossecurity.com\/papers\/session_fixation.pdf"},{"key":"2_CR9","unstructured":"Microsoft. X-Frame-Options (May 20, 2011), \n                    \n                      http:\/\/blogs.msdn.com\/b\/ie\/archive\/2009\/01\/27\/ie8-security-part-vii-clickjacking-defenses.aspx"},{"key":"2_CR10","unstructured":"Mozilla. X-Frame-Options response header (May 20, 2011), \n                    \n                      https:\/\/developer.mozilla.org\/en\/the_x-frame-options_response_header"},{"key":"2_CR11","unstructured":"Mozilla. Csp (content security policy). Mozilla Developer Network (March 2009), \n                    \n                      https:\/\/developer.mozilla.org\/en\/Security\/CSP"},{"key":"2_CR12","unstructured":"MSDN. Mitigating Cross-site Scripting With HTTP-only Cookies (June 08, 2012), \n                    \n                      http:\/\/msdn.microsoft.com\/en-us\/library\/ms533046VS.85.aspx"},{"key":"2_CR13","unstructured":"Niemietz, M.: UI Redressing: Attacks and Countermeasures Revisited. In: CONFidence 2011 (2011)"},{"key":"2_CR14","unstructured":"Hansen, R.: Clickjacking (May 20, 2011), \n                    \n                      http:\/\/ha.ckers.org\/blog\/20080915\/clickjacking\/"},{"key":"2_CR15","unstructured":"Hansen, R., Grossman, J.: Clickjacking (May 20, 2011), \n                    \n                      http:\/\/www.sectheory.com\/clickjacking.htm"},{"key":"2_CR16","unstructured":"Ruderman, J.: The Same Origin Policy (August 2001), \n                    \n                      https:\/\/developer.mozilla.org\/En\/Same_origin_policy_for_JavaScript\n                    \n                    \n                   (June 08, 2012)"},{"key":"2_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1007\/978-3-642-11747-3_2","volume-title":"Engineering Secure Software and Systems","author":"P. Ryck De","year":"2010","unstructured":"De Ryck, P., Desmet, L., Heyman, T., Piessens, F., Joosen, W.: CsFire: Transparent Client-Side Mitigation of Malicious Cross-Domain Requests. In: Massacci, F., Wallach, D., Zannone, N. (eds.) ESSoS 2010. LNCS, vol.\u00a05965, pp. 18\u201334. Springer, Heidelberg (2010)"},{"key":"2_CR18","unstructured":"Rydstedt, G., Bursztein, E., Boneh, D., Jackson, C.: Busting Frame Busting: a Study of Clickjacking Vulnerabilities on Popular Sites. In: Proceedings of W2SP 2010 (2010)"},{"key":"2_CR19","unstructured":"Schrank, M., Braun, B., Johns, M., Posegga, J.: Session Fixation - the Forgotten Vulnerability? In: Proceedings of GI Sicherheit 2010 (2010)"},{"key":"2_CR20","unstructured":"W3C. HTML5 - The canvas element (September 24, 2011), \n                    \n                      http:\/\/www.w3.org\/TR\/html5\/the-canvas-element.html"},{"key":"2_CR21","unstructured":"W3C. HTML5 - The iframe element (August 29, 2011), \n                    \n                      http:\/\/www.w3.org\/TR\/html5\/the-iframe-element.html#the-iframe-element"},{"key":"2_CR22","unstructured":"Zhou, Y., Evans, D.: Why Aren\u2019t HTTP-only Cookies More Widely Deployed? In: Proceedings of W2SP 2010 (2010)"}],"container-title":["Lecture Notes in Computer Science","Trust, Privacy and Security in Digital Business"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-32287-7_2.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,4]],"date-time":"2021-05-04T07:59:57Z","timestamp":1620115197000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-32287-7_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642322860","9783642322877"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-32287-7_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2012]]}}}