Primer on Client-Side Web Security

  • Rijk, Philippe de (iMinds-DistriNet K
  • Desmet, Lieven (iMinds-DistriNet K
  • Piessens, Frank (iMinds-DistriNet K
  • et al.
N/ACitations
Citations of this article
19Readers
Mendeley users who have this article in their library.

Abstract

Have you ever wondered why all of a sudden, normal users start posting strange messages on social networks? Howwireless routers can be controlled remotely?Why eBayaccounts could be hijacked with a singleHTTPrequest? Orwhya newsWeb site suddenly shows a page from the Syrian ElectronicArmy?All of these incidents were possible due to attackers controlling some code within the victim’s browser, a result of the current state of practice inWeb security, which is less than stellar. As security researchers, we are concerned by the large gap between the state of practice and the currently available security technologies, which are often inspired by security research. In an effort to improve this situation, we have written this book, which gives a detailed view on the client-sideWeb security landscape.We explicitly focus on client-side security vulnerabilities, which are exploited from within a browser or explicitly target the browser, because they generally receive less attention compared to their server-side counterparts. In total, we cover 13 attacks, for which we give a detailed description, an overview of traditional mitigation techniques, and current state-of-the-art research. For each attack, wealso describe the current state of practice inWeb applications, and define the best practices to defend against these attacks in the modern age.

Cite

CITATION STYLE

APA

Rijk, Philippe de (iMinds-DistriNet, K. L., Desmet, Lieven (iMinds-DistriNet, K. L., Piessens, Frank (iMinds-DistriNet, K. L., & Johns, M. (SAP R. (2014). Primer on Client-Side Web Security, 111.

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free