Prikladnaya Diskretnaya Matematika. Supplement
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Prikl. Diskr. Mat. Suppl.:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Prikladnaya Diskretnaya Matematika. Supplement, 2015, Issue 8, Pages 85–89
DOI: https://doi.org/10.17223/2226308X/8/32
(Mi pdma220)
 

This article is cited in 1 scientific paper (total in 1 paper)

Mathematical Foundations of Computer Security

Non-invasive integrity control method for cookie in web applications

D. N. Kolegov, O. V. Broslavsky, N. E. Oleksov

Tomsk State University, Tomsk
Full-text PDF (532 kB) Citations (1)
References:
Abstract: A non-invasive integrity control method for cookies in web applications is suggested. The method is based on cryptographic protocols and keying hash functions. It involves the creation and usage of a set of auxiliary cookies. So for every controlled cookie C, there is a cookie containing hmac from cookie C and its expiration date as well as the value of the expiration date itself. This allows to control the value integrity for C and to ensure the impossibility of its deletion. Besides, there is an auxiliary cookie allowing to control integrity of path, domain and other attributes for all controlled cookies. The value integrity for this auxiliary cookie is also provided with the help of hmac. Generally speaking, the proposed method solves the following problems in web applications: providing the integrity value for cookies; protecting cookies from deletion and prolongation, that is, from changing the attribute “expires” and setting the flag session; providing the value integrity for attributes “path” and “domain”; controlling the transmission of cookie with the attribute “secure” over a secure connection. All these functions of the method are quite capable of being implemented in web applications in non-invasive way. Thus, the method can be used in non-invasive protection mechanisms against web application attacks employing cookies as an attack vector.
Keywords: cryptographic protocols, hash functions, web application, HTTP cookie.
Document Type: Article
UDC: 004.94
Language: Russian
Citation: D. N. Kolegov, O. V. Broslavsky, N. E. Oleksov, “Non-invasive integrity control method for cookie in web applications”, Prikl. Diskr. Mat. Suppl., 2015, no. 8, 85–89
Citation in format AMSBIB
\Bibitem{KolBroOle15}
\by D.~N.~Kolegov, O.~V.~Broslavsky, N.~E.~Oleksov
\paper Non-invasive integrity control method for cookie in web applications
\jour Prikl. Diskr. Mat. Suppl.
\yr 2015
\issue 8
\pages 85--89
\mathnet{http://mi.mathnet.ru/pdma220}
\crossref{https://doi.org/10.17223/2226308X/8/32}
Linking options:
  • https://www.mathnet.ru/eng/pdma220
  • https://www.mathnet.ru/eng/pdma/y2015/i8/p85
  • This publication is cited in the following 1 articles:
    Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Prikladnaya Diskretnaya Matematika. Supplement
    Statistics & downloads:
    Abstract page:124
    Full-text PDF :61
    References:30
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2024