The Experts below are selected from a list of 150 Experts worldwide ranked by ideXlab platform

Jens-matthias Bohli - One of the best experts on this subject based on the ideXlab platform.

  • ICCSA (3) - A framework for robust group key agreement
    Computational Science and Its Applications - ICCSA 2006, 2006
    Co-Authors: Jens-matthias Bohli
    Abstract:

    Considering a protocol of Tseng, we show that a group key agreement protocol that resists attacks by malicious insiders in the authenticated broadcast model, loses this security when it is transfered into an unauthenticated point-to-point network with the protocol compiler introduced by Katz and Yung. We develop a protocol framework that allows to transform passively secure protocols into protocols that provide security against malicious insiders and active adversaries in an unauthenticated point-to-point network and, in contrast to existing protocol compilers, does not increase the number of rounds. Our protocol particularly uses the Session Identifier to achieve the security. By applying the framework to the Burmester-Desmedt protocol we obtain a new 2 round protocol that is provably secure against active adversaries and malicious participants.

  • A Framework for Robust Group Key Agreement
    Lecture Notes in Computer Science, 2006
    Co-Authors: Jens-matthias Bohli
    Abstract:

    Considering a protocol of Tseng, we show that a group key agreement protocol that resists attacks by malicious insiders in the authenticated broadcast model, loses this security when it is transfered into an unauthenticated point-to-point network with the protocol compiler introduced by Katz and Yung. We develop a protocol framework that allows to transform passively secure protocols into protocols that provide security against malicious insiders and active adversaries in an unauthenticated point-to-point network and, in contrast to existing protocol compilers, does not increase the number of rounds. Our protocol particularly uses the Session Identifier to achieve the security. By applying the framework to the Burmester-Desmedt protocol we obtain a new 2 round protocol that is provably secure against active adversaries and malicious participants.

  • VIETCRYPT - Towards provably secure group key agreement building on group theory
    Progress in Cryptology - VIETCRYPT 2006, 2006
    Co-Authors: Jens-matthias Bohli, Benjamin Glas, Rainer Steinwandt
    Abstract:

    Known proposals for key establishment schemes based on combinatorial group theory are often formulated in a rather informal manner. Typically, issues like the choice of a Session Identifier and parallel protocol executions are not addressed, and no security proof in an established model is provided. Successful attacks against proposed parameter sets for braid groups further decreased the attractivity of combinatorial group theory as a candidate platform for cryptography. We present a 2-round group key agreement protocol that can be proven secure in the random oracle model if a certain group-theoretical problem is hard. The security proof builds on a framework of Bresson et al., and explicitly addresses some issues concerning malicious insiders and also forward secrecy. While being designed as a tool for basing group key agreement on non-abelian groups, our framework also yields a 2-round group key agreement basing on a Computational Diffie-Hellman assumption.

Nadjib Badache - One of the best experts on this subject based on the ideXlab platform.

  • CODASPY - Sound and Static Analysis of Session Fixation Vulnerabilities in PHP Web Applications
    Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy, 2017
    Co-Authors: Abdelouahab Amira, Abdelraouf Ouadjaout, Abdelouahid Derhab, Nadjib Badache
    Abstract:

    Web applications use authentication mechanisms to provide user-friendly content to users. However, some dangerous techniques like Session fixation attacks target these mechanisms, by making the legitimate user use a Session Identifier that is controlled by the attacker. In this way, he can then impersonate the legitimate user without the need to know his credentials. In this paper, we present SAWFIX, a PHP static analyzer that checks web applications for Session fixation vulnerabilities. To the best of our knowledge, SAWFIX is the first analyzer that checks exhaustively for this type of vulnerabilities, while the other methods only ensure partial correctness that is limited to a fraction of possible executions. SAWFIX is based on abstract interpretation, which is a theory for approximating the semantics of programs and allows designing static analyzers that are fully automatic and sound by construction. We implemented a prototype of our approach and tested it on several complex web applications. We obtained promising results in terms of detection accuracy and processing time, which reflects the efficiency of our system.

  • Sound and Static Analysis of Session Fixation Vulnerabilities in PHP Web Applications
    2017
    Co-Authors: Abdelouahab Amira, Abdelraouf Ouadjaout, Abdelouahid Derhab, Nadjib Badache
    Abstract:

    Web applications use authentication mechanisms to provide user-friendly content to users. However, some dangerous techniques like Session fixation attacks target these mechanisms, by making the legitimate user use a Session Identifier that is controlled by the attacker. In this way, he can then impersonate the legitimate user without the need to know his credentials. In this paper, we present SAWFIX, a PHP static analyzer that checks web applications for Session fixation vulnerabilities. To the best of our knowledge, SAWFIX is the first analyzer that checks exhaustively for this type of vulnerabilities, while the other methods only ensure partial correctness that is limited to a fraction of possible executions. SAWFIX is based on abstract interpretation, which is a theory for approximating the semantics of programs and allows designing static analyzers that are fully automatic and sound by construction. We implemented a prototype of our approach and tested it on several complex web applications. We obtained promising results in terms of detection accuracy and processing time, which reflects the efficiency of our system.

Abdelouahab Amira - One of the best experts on this subject based on the ideXlab platform.

  • CODASPY - Sound and Static Analysis of Session Fixation Vulnerabilities in PHP Web Applications
    Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy, 2017
    Co-Authors: Abdelouahab Amira, Abdelraouf Ouadjaout, Abdelouahid Derhab, Nadjib Badache
    Abstract:

    Web applications use authentication mechanisms to provide user-friendly content to users. However, some dangerous techniques like Session fixation attacks target these mechanisms, by making the legitimate user use a Session Identifier that is controlled by the attacker. In this way, he can then impersonate the legitimate user without the need to know his credentials. In this paper, we present SAWFIX, a PHP static analyzer that checks web applications for Session fixation vulnerabilities. To the best of our knowledge, SAWFIX is the first analyzer that checks exhaustively for this type of vulnerabilities, while the other methods only ensure partial correctness that is limited to a fraction of possible executions. SAWFIX is based on abstract interpretation, which is a theory for approximating the semantics of programs and allows designing static analyzers that are fully automatic and sound by construction. We implemented a prototype of our approach and tested it on several complex web applications. We obtained promising results in terms of detection accuracy and processing time, which reflects the efficiency of our system.

  • Sound and Static Analysis of Session Fixation Vulnerabilities in PHP Web Applications
    2017
    Co-Authors: Abdelouahab Amira, Abdelraouf Ouadjaout, Abdelouahid Derhab, Nadjib Badache
    Abstract:

    Web applications use authentication mechanisms to provide user-friendly content to users. However, some dangerous techniques like Session fixation attacks target these mechanisms, by making the legitimate user use a Session Identifier that is controlled by the attacker. In this way, he can then impersonate the legitimate user without the need to know his credentials. In this paper, we present SAWFIX, a PHP static analyzer that checks web applications for Session fixation vulnerabilities. To the best of our knowledge, SAWFIX is the first analyzer that checks exhaustively for this type of vulnerabilities, while the other methods only ensure partial correctness that is limited to a fraction of possible executions. SAWFIX is based on abstract interpretation, which is a theory for approximating the semantics of programs and allows designing static analyzers that are fully automatic and sound by construction. We implemented a prototype of our approach and tested it on several complex web applications. We obtained promising results in terms of detection accuracy and processing time, which reflects the efficiency of our system.

K. Satish Kumar - One of the best experts on this subject based on the ideXlab platform.

  • Web Application Protection from Wide Range of Web Vulnerabilities
    Data mining and knowledge engineering, 2010
    Co-Authors: K. Venkatesh Sharma, K. Satish Kumar
    Abstract:

    Adoption of web applications is increasing for multipurpose services. However, their correct functioning is mission critical for many businesses. At the same time, Web applications tend to be error prone and implementation vulnerabilities are readily and commonly exploited by attackers. The design of countermeasures that detect or prevent such vulnerabilities or protect against their exploitation is an important research challenge for the fields of software engineering and security engineering. In this paper we introduce a single J2EE based web application which can able to handle several vulnerabilities at application level, mainly these are related to injection types, cross site scripting, browser caching and also protecting the Session data dependency via changing Session Identifier at runtime, sequential access and Session expiration. By handling all these things together in an application we can protect our web application successfully from the common vulnerabilities.

Abdelouahid Derhab - One of the best experts on this subject based on the ideXlab platform.

  • CODASPY - Sound and Static Analysis of Session Fixation Vulnerabilities in PHP Web Applications
    Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy, 2017
    Co-Authors: Abdelouahab Amira, Abdelraouf Ouadjaout, Abdelouahid Derhab, Nadjib Badache
    Abstract:

    Web applications use authentication mechanisms to provide user-friendly content to users. However, some dangerous techniques like Session fixation attacks target these mechanisms, by making the legitimate user use a Session Identifier that is controlled by the attacker. In this way, he can then impersonate the legitimate user without the need to know his credentials. In this paper, we present SAWFIX, a PHP static analyzer that checks web applications for Session fixation vulnerabilities. To the best of our knowledge, SAWFIX is the first analyzer that checks exhaustively for this type of vulnerabilities, while the other methods only ensure partial correctness that is limited to a fraction of possible executions. SAWFIX is based on abstract interpretation, which is a theory for approximating the semantics of programs and allows designing static analyzers that are fully automatic and sound by construction. We implemented a prototype of our approach and tested it on several complex web applications. We obtained promising results in terms of detection accuracy and processing time, which reflects the efficiency of our system.

  • Sound and Static Analysis of Session Fixation Vulnerabilities in PHP Web Applications
    2017
    Co-Authors: Abdelouahab Amira, Abdelraouf Ouadjaout, Abdelouahid Derhab, Nadjib Badache
    Abstract:

    Web applications use authentication mechanisms to provide user-friendly content to users. However, some dangerous techniques like Session fixation attacks target these mechanisms, by making the legitimate user use a Session Identifier that is controlled by the attacker. In this way, he can then impersonate the legitimate user without the need to know his credentials. In this paper, we present SAWFIX, a PHP static analyzer that checks web applications for Session fixation vulnerabilities. To the best of our knowledge, SAWFIX is the first analyzer that checks exhaustively for this type of vulnerabilities, while the other methods only ensure partial correctness that is limited to a fraction of possible executions. SAWFIX is based on abstract interpretation, which is a theory for approximating the semantics of programs and allows designing static analyzers that are fully automatic and sound by construction. We implemented a prototype of our approach and tested it on several complex web applications. We obtained promising results in terms of detection accuracy and processing time, which reflects the efficiency of our system.