{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T14:38:13Z","timestamp":1775745493382,"version":"3.50.1"},"reference-count":32,"publisher":"IEEE","license":[{"start":{"date-parts":[[2018,8,1]],"date-time":"2018-08-01T00:00:00Z","timestamp":1533081600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2018,8,1]],"date-time":"2018-08-01T00:00:00Z","timestamp":1533081600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018,8]]},"DOI":"10.1109\/pst.2018.8514180","type":"proceedings-article","created":{"date-parts":[[2018,11,19]],"date-time":"2018-11-19T20:50:46Z","timestamp":1542660646000},"page":"1-5","source":"Crossref","is-referenced-by-count":13,"title":["Mitigating CSRF attacks on OAuth 2.0 Systems"],"prefix":"10.1109","author":[{"given":"Wanpeng","family":"Li","sequence":"first","affiliation":[{"name":"School of Computing, Mathematics, Digital Technology Manchester Metropolitan University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chris J","family":"Mitchell","sequence":"additional","affiliation":[{"name":"Information Security Group Royal Holloway, University of London"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Electrical, Electronic Engineering City, University of London"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref32","first-page":"495","article-title":"SSOScan: Automated testing of web applications for Single Sign-On vulnerabilities","author":"zhou","year":"2014","journal-title":"Proceedings of the 2014 USENIX Security Symposium"},{"key":"ref31","article-title":"Cross-site request forgeries: Exploitation and prevention","author":"zeller","year":"2008","journal-title":"BerichtPrinceton University"},{"key":"ref30","first-page":"651","article-title":"Model-based security testing: An empirical study on oauth 2.0 implementations","author":"yang","year":"0","journal-title":"Proc AsiaCCS 2016"},{"key":"ref10","first-page":"390","article-title":"The murphi verification system","author":"dill","year":"1996","journal-title":"Proc CAV &#x2019;96 volume 1102 of LNCS"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978385"},{"key":"ref12","author":"fielding","year":"1999","journal-title":"RFC 2616 Hypertext Transfer Protocol&#x2014 HTTP\/1 1"},{"key":"ref13","author":"hardt","year":"2012","journal-title":"RFC 6749 The OAuth 2 0 Authorization Framework"},{"key":"ref14","author":"jackson","year":"2010","journal-title":"Alloy 4 1"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SECCOMW.2006.359531"},{"key":"ref16","first-page":"529","article-title":"Security issues in OAuth 2.0 SSO imple- mentations","author":"li","year":"2014","journal-title":"Proc ISC 2014 volume 8783 of LNCS"},{"key":"ref17","first-page":"357","article-title":"Analysing the security of Google&#x2019;s implementation of OpenID Connect","author":"li","year":"2016","journal-title":"Proc DIMVA 2016 volume 9721 of LNCS"},{"key":"ref18","author":"lodderstedt","year":"2013","journal-title":"IETF RFC 6819 Oauth 2 0 threat model and security considerations"},{"key":"ref19","first-page":"238","article-title":"Defeating cross-site request forgery attacks with browser-enforced authenticity protection","author":"mao","year":"2009","journal-title":"Proc FC 2009 volume 5628 of LNCS"},{"key":"ref28","year":"2017","journal-title":"Referrer Policy"},{"key":"ref4","author":"blanchet","year":"0","journal-title":"ProVerif Cryptographic protocol verifier in the formal model"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382238"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455782"},{"key":"ref6","first-page":"526","article-title":"Universally composable security analysis of OAuth v2.0","volume":"2011","author":"chari","year":"2011","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.30"},{"key":"ref5","article-title":"Cross site reference forgery: An introduction to a common web application weakness","author":"burns","year":"2005","journal-title":"Security Partners"},{"key":"ref8","author":"de medeiros","year":"2014","journal-title":"OpenID Connect Session Management"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660323"},{"key":"ref2","author":"bansal","year":"2011","journal-title":"WebSpi and Web Application Models"},{"key":"ref9","first-page":"100","article-title":"Automatic and precise client-side protection against CSRF attacks","author":"de ryck","year":"2011","journal-title":"ESORICS 2011 volume 6879 of LNCS"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-140503"},{"key":"ref20","year":"2017","journal-title":"OWASP Top Ten Project"},{"key":"ref22","author":"sakimura","year":"2014","journal-title":"Openid Connect Core 1 0"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CSNT.2011.141"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/2557547.2557588"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2010.12"},{"key":"ref26","author":"slack","year":"2011","journal-title":"Murphi analysis of OAuth 2 0 implicit grant flow"},{"key":"ref25","first-page":"239","article-title":"More guidelines than rules: CSRF vulnerabilities from noncompliant OAuth 2.0 implementations","author":"shernan","year":"2015","journal-title":"Proc DIMVA 2015 volume 9148 of LNCS"}],"event":{"name":"2018 16th Annual Conference on Privacy, Security and Trust (PST)","location":"Belfast, Ireland","start":{"date-parts":[[2018,8,28]]},"end":{"date-parts":[[2018,8,30]]}},"container-title":["2018 16th Annual Conference on Privacy, Security and Trust (PST)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8498146\/8514154\/08514180.pdf?arnumber=8514180","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,23]],"date-time":"2023-02-23T17:47:29Z","timestamp":1677174449000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8514180\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,8]]},"references-count":32,"URL":"https:\/\/doi.org\/10.1109\/pst.2018.8514180","relation":{},"subject":[],"published":{"date-parts":[[2018,8]]}}}