Accomplishments

Prevention of Session Hijacking Attack Using Enhanced Session Binding Techniques


  • Details
  • Share
Category
Articles
Publisher
Icecs
Publishing Date
01-Feb-2016
volume
x
Issue
x
Pages
x
  • Abstract

Computer networks are vulnerable to numerous types of attacks. The session hijacking attack is the most effective and successful attack attempted by the adversaries till date. In this paper we have analyzed the underlying problem and provided a customized solution to prevent session hijacking efficiently. We have also developed an enhanced technique with a preventive mechanism against the session hijacking attack. The key idea is that we have used reverse proxy server that binds the application level and network level credentials, and will generate disposable One-Time Cookies (OTC) for each activity of the users. The binding and OTC information is supported with a mechanism that can detect change of browser for current session. This prototype prevents adversary from hijacking the session, since users are bind with the machine and browser for each session and with new disposable cookie for each request in a session. Implementation of this technique has improved the security of web application with minimal impact on performance and scalability.

Apply Now Enquire Now