作者: Bastian Braun , Caspar Gries , Benedikt Petschkuhn , Joachim Posegga
DOI: 10.1007/978-3-642-55415-5_22
关键词:
摘要: Modern web applications frequently implement complex control flows, which require the users to perform actions in a given order. Users interact with application by sending HTTP requests parameters and response receive pages hyperlinks that indicate expected next actions. If takes for granted user sends only those parameters, malicious can exploit this assumption crafting harming requests. We analyze recent attacks on respect user-defined identify their root cause missing enforcement of allowed Based result, we provide our approach, named Ghostrail, control-flow monitor is applicable legacy as well newly developed applications. It observes incoming lets pass were provided steps last page. Ghostrail protects against race condition exploits, manipulation unsolicited request sequences, forceful browsing. evaluate approach show it neither needs training phase nor manual policy definition while suitable broad range technologies.