Browse > Article
http://dx.doi.org/10.13089/JKIISC.2008.18.1.103

An Analysis of Replay Attack Vulnerability on Single Sign-On Solutions  

Maeng, Young-Jae (Information Security Research Laboratory, INHA University)
Nyang, Dae-Hun (Information Security Research Laboratory, INHA University)
Abstract
Single Sign-On is an authentication scheme that enables a user to authenticate once and then to access to the resources of multiple software systems without re-authentication. As web services are being integrated into a single groupware, more web sites are adopting for user convenience. However, these Single Sign-On services are very dependent upon the cookies and thus, simple eavesdropping enables attackers to hiject the user's session. Even worse, the attacker who hijacked one session can move to another site through the Single Sign-On. In this paper, we show the vulnerabilities of the top ranked sites regarding this point of view and also propose a way to protect a user's session.
Keywords
Single Sign-On; Cookie; Session; Replay Attack; Hypertext Transfer Protocol;
Citations & Related Records
연도 인용수 순위
  • Reference
1 Gary Ellison, Jeff Hodges, Susan Landau, "Security and Privacy Concerns of Internet Single Sign-On", Liberty v1.6, September 2002
2 B. Pfitzmann, B. Waidner, "Token-based web Single Signon with Enabled Clients", IBM Research Report RZ 3458 (#93844), November (2002)
3 Andreas Pashalidis, Chris J. Mitchell, "A Taxonomy of Single Sign-On Systems", Proceedings of the 8th Australasian Conference, LNCS 2727, 2003
4 V. Samar, "Single Sign-On Using Cookies for Web Applications," WET ICE'99, June 1999
5 http://www.w3.org/P3P/
6 http://www.adobe.com/support/flash/action_scri pts/local_shared_object/
7 http://www.kaoni.com
8 Jan De Clercq, "Single Sign-On Architectures", Proceedings of the International Conference on Infrastructure Security, pp. 40-58, 2002   DOI
9 Eric Rescorla, "SSL and TLS", Addison- Wesley, Reading, Massachusetts, 2001
10 J Park and R. Sandhu, "Secure Cookies on the Web," IEEE Internet Computing, Aug. 2000
11 http://www.boutell.com/newfaq/creating/scriptp ass.html
12 http://www.nets.co.kr
13 http://www.sebitsoft.com