Autor/a

García Alfaro, Joaquín

Navarro Arribas, Guillermo

Otros/as autores/as

Universitat Oberta de Catalunya. K-ryptography and Information Security for Open Networks (KISON)

Fecha de publicación

2010-02-16T11:56:43Z

2010-02-16T11:56:43Z

2007



Resumen

Security is becoming one of the major concerns for web applications and other Internet based services, which are becoming pervasive in all kinds of business models and organizations. Web applications must therefore include, in addition to the expected value offered to their users, reliable mechanisms to ensure their security. In this paper, we focus on the specific problem of preventing cross-site scripting attacks against web applications. We present a study of this kind of attacks, and survey current approaches for their prevention. The advantages and limitations of each proposal are discussed, and an alternative solution is introduced. Our proposition is based on the use of X.509 certificates, and XACML for the expression of authorization policies. By using our solution, developers and/or administrators of a given web application can specifically express its security requirements from the server side, and require the proper enforcement of such requirements on a compliant client. This strategy is seamlessly integrated in generic web applications by relaying in the SSL and secure redirect calls.

Tipo de documento

Artículo

Lengua

Inglés

Materias y palabras clave

Internet -- Security measures; Computer networks -- Security measures; Computer security; Internet -- Mesures de seguretat; Ordinadors, Xarxes d' -- Mesures de seguretat; Informàtica -- Mesures de seguretat; Internet -- Medidas de seguridad; Ordenadores, Redes de -- Medidas de seguridad; Informática -- Medidas de seguridad

Derechos

The original publication is available at http://www.springerlink.com/content/e9057385714r6171

Este ítem aparece en la(s) siguiente(s) colección(ones)

Articles [361]