SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities

被引:0
|
作者
Zhou, Yuchen [1 ]
Evans, David [1 ]
机构
[1] Univ Virginia, Charlottesville, VA 22903 USA
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Correctly integrating third-party services into web applications is challenging, and mistakes can have grave consequences when third-party services are used for security-critical tasks such as authentication and authorization. Developers often misunderstand integration requirements and make critical mistakes when integrating services such as single sign-on APIs. Since traditional programming techniques are hard to apply to programs running inside black-box web servers, we propose to detect vulnerabilities by probing behaviors of the system. This paper describes the design and implementation of SSOScan, an automatic vulnerability checker for applications using Facebook Single Sign-On (SSO) APIs. We used SSOScan to study the twenty thousand top-ranked websites for five SSO vulnerabilities. Of the 1660 sites in our study that employ Facebook SSO, over 20% were found to suffer from at least one serious vulnerability.
引用
收藏
页码:495 / 510
页数:16
相关论文
共 50 条
  • [1] MoSSOT: An Automated Blackbox Tester for Single Sign-On Vulnerabilities in Mobile Applications
    Shi, Shangcheng
    Wang, Xianbo
    Lau, Wing Cheong
    [J]. PROCEEDINGS OF THE 2019 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS '19), 2019, : 269 - 282
  • [2] Single Sign-On Assistant: An Authentication Broker for Web Applications
    Zhu, Fei
    Diao, Hongjun
    [J]. THIRD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING: WKDD 2010, PROCEEDINGS, 2010, : 146 - 149
  • [3] Single sign-on for Java Web Start applications using MyProxy
    National Center for Supercomputing Applications, 1205 W. Clark St., Urbana, IL 61801, United States
    [J]. ACM SIGSAC, 1600, 95-101 (2006):
  • [4] GridCertLib: A Single Sign-on Solution for Grid Web Applications and Portals
    Murri, Riccardo
    Kunszt, Peter Z.
    Maffioletti, Sergio
    Tschopp, Valery
    [J]. JOURNAL OF GRID COMPUTING, 2011, 9 (04) : 441 - 453
  • [5] GridCertLib: A Single Sign-on Solution for Grid Web Applications and Portals
    Riccardo Murri
    Peter Z. Kunszt
    Sergio Maffioletti
    Valery Tschopp
    [J]. Journal of Grid Computing, 2011, 9 : 441 - 453
  • [6] CHARACTERIZATION OF WEB SINGLE SIGN-ON PROTOCOLS
    Beltran, Victoria
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2016, 54 : 24 - 30
  • [7] Single sign-on to the web with an EMV card
    Boyd, David J.
    [J]. PROCEEDINGS OF THE 2008 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS: CTS 2008, 2008, : 112 - 120
  • [8] Single sign-on protocol for web services
    Zheng, Dong-Xi
    Tang, Shao-Hua
    Li, Shao-Fa
    [J]. Huanan Ligong Daxue Xuebao/Journal of South China University of Technology (Natural Science), 2005, 33 (02): : 65 - 69
  • [9] A single sign-on framework for web-services-based distributed applications
    Hillenbrand, M
    Götze, J
    Müller, J
    Müller, P
    [J]. CONTEL 2005: PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS, VOLS 1 AND 2, 2005, : 273 - 279
  • [10] A Single Sign-On Scheme for Cross Domain Web Applications Based on SOA
    He, Enze
    Wen, Qiaoyan
    [J]. INTERNET OF THINGS-BK, 2012, 312 : 581 - 589