Provably sound browser-based enforcement of web session integrity

M Bugliesi, S Calzavara, R Focardi… - 2014 IEEE 27th …, 2014 - ieeexplore.ieee.org
web authentication security. In this paper we provide such foundations, by introducing a novel
notion of web session integrity… plan to investigate how to enforce web session integrity in a …

[PDF][PDF] Provably Sound Browser-Based Enforcement of Web Session Integrity

MBSCR Focardi, WKM Tempesta - dais.unive.it
… , by introducing a novel notion of web session integrity, which allows us to capture … of a web
browser that provides a fullfledged and provably sound enforcement of web session integrity. …

Enforcing Session Integrity in the World" Wild" Web

M Tempesta - 2015 - dspace.unive.it
… a novel notion of web session integrity, which allows to … complete and provably sound
enforcement of web session integrity. … A similar idea is implemented in Zan [101], a browser-based

{WPSE}: Fortifying Web Protocols via {Browser-Side} Security Monitoring

S Calzavara, R Focardi, M Maffei… - 27th USENIX Security …, 2018 - usenix.org
… for web protocols, that is, the confidentiality and integrity of … is also important to ensure
session integrity. An example of an … Combining our approach with browser-based information …

Surviving the web: A journey into web session security

S Calzavara, R Focardi, M Squarcina… - ACM Computing Surveys …, 2017 - dl.acm.org
… : passive content like images, audio tracks, or videos cannot modify … confidentiality and the
integrity of a web session. Specifically, … Browser-based information flow control is a promising …

Client side web session integrity as a non-interference property

W Khan, S Calzavara, M Bugliesi, W De Groef… - … Systems Security: 10th …, 2014 - Springer
… an enforcement mechanism and prove it secure. Then, in Section 4 we show how this applies
to web session integrity, and … Provably sound browser-based enforcement of web session

Testing for integrity flaws in web sessions

S Calzavara, A Rabitti, A Ragazzo… - … Security–ESORICS 2019 …, 2019 - Springer
… Classic attacks like session hijacking, session fixation and cross-site request … for web
session security, because they allow the attacker to breach the integrity of honest users’ sessions

[PDF][PDF] Client side web session integrity as a non-interference property: Extended version with proofs

W Khan, S Calzavara, M Bugliesi, W De Groef… - 2014 - cs.kuleuven.be
… an enforcement mechanism and prove it secure. Then, in Section 4 we show how this applies
to web session integrity, and … Provably sound browser-based enforcement of web session

Webspec: Towards machine-checked analysis of browser security mechanisms

L Veronese, B Farinier, P Bernardo… - … IEEE Symposium on …, 2023 - ieeexplore.ieee.org
integrity guarantees in the redirected request over the HTTP method and the body of the
original request [43], (iv) 307 Temporary Redirect, redirection enforcing … a Web session integrity

Towards Browser Controls to Protect Cookies from Malicious Extensions

L Tyler, IDO Nunes - arXiv preprint arXiv:2405.06830, 2024 - arxiv.org
… of attacks such as Session Hijacking and Session Fixation that … to identify browser instances
and enforce the Tracked and … Furthermore, none of these controls address cookie integrity