Gesellschaft für Informatik e.V.

Lecture Notes in Informatics


Sicherheit, Schutz und Zuverlässigkeit (SICHERHEIT 2012) P-195, 111-122 (2012).

Gesellschaft für Informatik, Bonn
2012


Copyright © Gesellschaft für Informatik, Bonn

Contents

Towards stateless, client-side driven cross-site request forgery protection for web applications

Sebastian Lekies , Walter Tighzert and Martin Johns

Abstract


Cross-site request forgery (CSRF) is one of the dominant threats in the Web application landscape. In this paper, we present a lightweight and stateless protection mechanism that can be added to an existing application without requiring changes to the application's code. The key functionality of the approach, which is based on the double-submit technique, is purely implemented on the client-side. This way full coverage of client-side generation of HTTP requests is provided.


Full Text: PDF

Gesellschaft für Informatik, Bonn
ISBN 978-3-88579-289-5


Last changed 04.10.2013 18:37:29