{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:15:23Z","timestamp":1750306523154,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,11,7]],"date-time":"2014-11-07T00:00:00Z","timestamp":1415318400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,11,7]]},"DOI":"10.1145\/2664168.2664171","type":"proceedings-article","created":{"date-parts":[[2014,11,7]],"date-time":"2014-11-07T17:10:54Z","timestamp":1415380254000},"page":"105-116","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Guardians of the Clouds"],"prefix":"10.1145","author":[{"given":"Andreas","family":"Mayer","sequence":"first","affiliation":[{"name":"Adolf W\u00fcrth GmbH &amp; Co. KG, K\u00fcnzelsau-Gaisbach, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marcus","family":"Niemietz","sequence":"additional","affiliation":[{"name":"Horst G\u00f6rtz Institute for IT-Security, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vladislav","family":"Mladenov","sequence":"additional","affiliation":[{"name":"Horst G\u00f6rtz Institute for IT-Security, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"J\u00f6rg","family":"Schwenk","sequence":"additional","affiliation":[{"name":"Horst G\u00f6rtz Institute for IT-Security, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2014,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Apache Software Foundation. JMeter Project. http:\/\/jmeter.apache.org.  Apache Software Foundation. JMeter Project. http:\/\/jmeter.apache.org."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"A.\n       \n      Armando R.\n       \n      Carbone L.\n       \n      Compagna J.\n       \n      Cu\u00e9llar G.\n       \n      Pellegrino and \n      \n      \n      A.\n       \n      Sorniotti\n      \n  \n  . \n  From Multiple Credentials to Browser-Based Single Sign-On: Are We More Secure? In SEC volume \n  354\n   of \n  IFIP Advances in Information and Communication Technology pages \n  68\n  --\n  79\n  . \n  Springer 2011\n  .  A. Armando R. Carbone L. Compagna J. Cu\u00e9llar G. Pellegrino and A. Sorniotti. From Multiple Credentials to Browser-Based Single Sign-On: Are We More Secure? In SEC volume 354 of IFIP Advances in Information and Communication Technology pages 68--79. Springer 2011.","DOI":"10.1007\/978-3-642-21424-0_6"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456396.1456397"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"A. Barth. HTTP State Management Mechanism. RFC 6265 (Proposed Standard) Apr. 2011.  A. Barth. HTTP State Management Mechanism. RFC 6265 (Proposed Standard) Apr. 2011.","DOI":"10.17487\/rfc6265"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772701"},{"key":"e_1_3_2_1_6_1","unstructured":"Bitium Inc. Bitium. https:\/\/www.bitium.com\/ 2014.  Bitium Inc. Bitium. https:\/\/www.bitium.com\/ 2014."},{"key":"e_1_3_2_1_7_1","unstructured":"E. Butler. Firesheep 2010. http:\/\/codebutler.com\/firesheep\/.  E. Butler. Firesheep 2010. http:\/\/codebutler.com\/firesheep\/."},{"key":"e_1_3_2_1_8_1","unstructured":"Cantor S. et al. Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0. http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-core-2.0-os.pdf Mar. 2005.  Cantor S. et al. Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0. http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-core-2.0-os.pdf Mar. 2005."},{"key":"e_1_3_2_1_9_1","unstructured":"Cantor S. et al. Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0. OASIS Standard 15.03.2005 Mar. 2005. http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-profiles-2.0-os.pdf.  Cantor S. et al. Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0. OASIS Standard 15.03.2005 Mar. 2005. http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-profiles-2.0-os.pdf."},{"key":"e_1_3_2_1_10_1","first-page":"2014","author":"Carnegie Mellon University","year":"1995","journal-title":"CERT Coordination Center"},{"key":"e_1_3_2_1_11_1","unstructured":"CERT. Advisory CA-2000-02 Malicious HTML Tags Embedded in Client Web Requests 2000. http:\/\/www.cert.org\/advisories\/CA-2000-02.html.  CERT. Advisory CA-2000-02 Malicious HTML Tags Embedded in Client Web Requests 2000. http:\/\/www.cert.org\/advisories\/CA-2000-02.html."},{"key":"e_1_3_2_1_12_1","unstructured":"Cloudseal OU. Cloudseal. http:\/\/www.cloudseal.com\/ 2011--2014.  Cloudseal OU. Cloudseal. http:\/\/www.cloudseal.com\/ 2011--2014."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1124772.1124861"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"T. Dierks and E. Rescorla. The Transport Layer Security (TLS) Protocol Version 1.2. RFC 5246 (Proposed Standard) Aug. 2008. Updated by RFCs 5746 5878 6176.  T. Dierks and E. Rescorla. The Transport Layer Security (TLS) Protocol Version 1.2. RFC 5246 (Proposed Standard) Aug. 2008. Updated by RFCs 5746 5878 6176.","DOI":"10.17487\/rfc5246"},{"volume-title":"21st USENIX Security Symposium","year":"2012","author":"Dietz M.","key":"e_1_3_2_1_15_1"},{"volume-title":"NDSS","year":"2010","author":"Finifter M.","key":"e_1_3_2_1_16_1"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242661"},{"volume-title":"10th USENIX Security Symposium, Washington D.C.","year":"2001","author":"Fu K.","key":"e_1_3_2_1_18_1"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88313-5_8"},{"volume-title":"Annual Computer Security Applications Conference. IEEE Computer Society","year":"2003","author":"Gro' T.","key":"e_1_3_2_1_20_1"},{"volume-title":"IBM Research, 2006","year":"2006","author":"Gro' T.","key":"e_1_3_2_1_21_1"},{"volume-title":"NDSS","year":"2013","author":"B.","key":"e_1_3_2_1_22_1"},{"key":"e_1_3_2_1_23_1","unstructured":"R. Hansen and J. Grossman. Clickjacking 2008. http:\/\/www.sectheory.com\/clickjacking.htm.  R. Hansen and J. Grossman. Clickjacking 2008. http:\/\/www.sectheory.com\/clickjacking.htm."},{"volume-title":"Ruhr-University Bochum","year":"2012","author":"Heiderich M.","key":"e_1_3_2_1_24_1"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382276"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516723"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315254"},{"key":"e_1_3_2_1_28_1","unstructured":"N. Klingenstein. SAML V2.0 Holder-of-Key Web Browser SSO Profile. OASIS Committee Draft 02 05.07.2009 2009. http:\/\/www.oasis-open.org\/committees\/download.php\/33239\/sstc-saml-holder-of-key-browser-sso-cd-02.pdf.  N. Klingenstein. SAML V2.0 Holder-of-Key Web Browser SSO Profile. OASIS Committee Draft 02 05.07.2009 2009. http:\/\/www.oasis-open.org\/committees\/download.php\/33239\/sstc-saml-holder-of-key-browser-sso-cd-02.pdf."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00048-7"},{"key":"e_1_3_2_1_30_1","unstructured":"A. Manion. Vulnerability Note VU#867593 2003. http:\/\/www.kb.cert.org\/vuls\/id\/867593.  A. Manion. Vulnerability Note VU#867593 2003. http:\/\/www.kb.cert.org\/vuls\/id\/867593."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"C.\n       \n      Masone K.-H.\n       \n      Baek and \n      \n      \n      S.\n       \n      Smith\n      \n  \n  . \n  WSKE: Web Server Key Enabled Cookies. In S. Dietrich and R. Dhamija editors Financial Cryptography volume \n  4886\n   of \n  Lecture Notes in Computer Science pages \n  294\n  --\n  306\n  . \n  Springer 2007\n  .   C. Masone K.-H. Baek and S. Smith. WSKE: Web Server Key Enabled Cookies. In S. Dietrich and R. Dhamija editors Financial Cryptography volume 4886 of Lecture Notes in Computer Science pages 294--306. Springer 2007.","DOI":"10.1007\/978-3-540-77366-5_28"},{"volume-title":"NDSS","year":"2009","author":"Nadji Y.","key":"e_1_3_2_1_32_1"},{"key":"e_1_3_2_1_33_1","unstructured":"Okta Inc. Okta. http:\/\/www.okta.com\/ 2014.  Okta Inc. Okta. http:\/\/www.okta.com\/ 2014."},{"key":"e_1_3_2_1_34_1","unstructured":"OneLogin Inc. OneLogin. http:\/\/www.onelogin.com\/ 2010--2014.  OneLogin Inc. OneLogin. http:\/\/www.onelogin.com\/ 2010--2014."},{"key":"e_1_3_2_1_35_1","unstructured":"OWASP Foundation. Cross-Site Request Forgery (CSRF). https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF) 2013.  OWASP Foundation. Cross-Site Request Forgery (CSRF). https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF) 2013."},{"key":"e_1_3_2_1_36_1","unstructured":"OWASP Foundation. OWASP Top 10 - 2013: The Ten Most Critical Web Application Security Risks. https:\/\/www.owasp.org\/index.php\/Top_10_2013 2013.  OWASP Foundation. OWASP Top 10 - 2013: The Ten Most Critical Web Application Security Risks. https:\/\/www.owasp.org\/index.php\/Top_10_2013 2013."},{"key":"e_1_3_2_1_37_1","unstructured":"W. Palant. (CVE-2009-0357) XMLHttpRequest allows reading HTTPOnly cookies 2007. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=380418.  W. Palant. (CVE-2009-0357) XMLHttpRequest allows reading HTTPOnly cookies 2007. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=380418."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/4236.865085"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2003.1250582"},{"key":"e_1_3_2_1_40_1","unstructured":"J. Ruderman. Bug 154957 - iframe content background defaults to transparent 2002. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=154957.  J. Ruderman. Bug 154957 - iframe content background defaults to transparent 2002. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=154957."},{"key":"e_1_3_2_1_41_1","unstructured":"M. Slemko. Microsoft Passport to Trouble 2001. http:\/\/www.znep.com\/~marcs\/passport\/.  M. Slemko. Microsoft Passport to Trouble 2001. http:\/\/www.znep.com\/~marcs\/passport\/."},{"volume-title":"21st USENIX Security Symposium","year":"2012","author":"Somorovsky J.","key":"e_1_3_2_1_42_1"},{"key":"e_1_3_2_1_43_1","unstructured":"SSOCircle. SSOCircle. http:\/\/www.ssocircle.com\/ 2007--2014.  SSOCircle. SSOCircle. http:\/\/www.ssocircle.com\/ 2007--2014."},{"key":"e_1_3_2_1_44_1","unstructured":"P. Stone. Next Generation Clickjacking. http:\/\/www.contextis.co.uk\/documents\/5\/Context-Clickjacking_white_paper.pdf April 2010.  P. Stone. Next Generation Clickjacking. http:\/\/www.contextis.co.uk\/documents\/5\/Context-Clickjacking_white_paper.pdf April 2010."},{"key":"e_1_3_2_1_45_1","unstructured":"D. Strom. Single sign-on moves to the cloud. http:\/\/www.networkworld.com\/article\/2161919\/access-control\/single-sign-on-moves-to-the-cloud.html 2012.  D. Strom. Single sign-on moves to the cloud. http:\/\/www.networkworld.com\/article\/2161919\/access-control\/single-sign-on-moves-to-the-cloud.html 2012."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382238"},{"key":"e_1_3_2_1_47_1","unstructured":"Uninett AS. SimpleSAMLphp Project 2014. http:\/\/www.simplesamlphp.org.  Uninett AS. SimpleSAMLphp Project 2014. http:\/\/www.simplesamlphp.org."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.30"},{"key":"e_1_3_2_1_49_1","unstructured":"Wikipedia. Saml-based products and services. http:\/\/en.wikipedia.org\/wiki\/SAML-based_products_and_services March 2014.  Wikipedia. Saml-based products and services. http:\/\/en.wikipedia.org\/wiki\/SAML-based_products_and_services March 2014."},{"key":"e_1_3_2_1_50_1","unstructured":"WSO2 Inc. WSO2 StratosLive. https:\/\/stratoslive.wso2.com\/ 2014.  WSO2 Inc. WSO2 StratosLive. https:\/\/stratoslive.wso2.com\/ 2014."},{"volume-title":"NDSS","year":"2013","author":"Xing L.","key":"e_1_3_2_1_51_1"},{"volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","year":"2014","author":"Yuchen Zhou D. E.","key":"e_1_3_2_1_52_1"},{"key":"e_1_3_2_1_53_1","unstructured":"Y. Zhou and D. Evans. Why Aren't HTTP-only Cookies More Widely Deployed? In Web 2.0 Security and Privacy 2010 (W2SP) 2010.  Y. Zhou and D. Evans. Why Aren't HTTP-only Cookies More Widely Deployed? In Web 2.0 Security and Privacy 2010 (W2SP) 2010."},{"key":"e_1_3_2_1_54_1","first-page":"8","article-title":"The Anatomy of Cros Site Scripting","author":"Zuchlinski G.","year":"2003","journal-title":"Hitchhiker's World"}],"event":{"name":"CCS'14: 2014 ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Scottsdale Arizona USA","acronym":"CCS'14"},"container-title":["Proceedings of the 6th edition of the ACM Workshop on Cloud Computing Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2664168.2664171","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2664168.2664171","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:12:01Z","timestamp":1750227121000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2664168.2664171"}},"subtitle":["When Identity Providers Fail"],"short-title":[],"issued":{"date-parts":[[2014,11,7]]},"references-count":54,"alternative-id":["10.1145\/2664168.2664171","10.1145\/2664168"],"URL":"https:\/\/doi.org\/10.1145\/2664168.2664171","relation":{},"subject":[],"published":{"date-parts":[[2014,11,7]]},"assertion":[{"value":"2014-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}