Bulwark: Holistic and Verified Security Monitoring of Web Protocols

01/15/2021
by   Lorenzo Veronese, et al.
0

Modern web applications often rely on third-party services to provide their functionality to users. The secure integration of these services is a non-trivial task, as shown by the large number of attacks against Single Sign On and Cashier-as-a-Service protocols. In this paper we present Bulwark, a new automatic tool which generates formally verified security monitors from applied pi-calculus specifications of web protocols. The security monitors generated by Bulwark offer holistic protection, since they can be readily deployed both at the client side and at the server side, thus ensuring full visibility of the attack surface against web protocols. We evaluate the effectiveness of Bulwark by testing it against a pool of vulnerable web applications that use the OAuth 2.0 protocol or integrate the PayPal payment system.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/24/2018

SPX: Preserving End-to-End Security for Edge Computing

Beyond point solutions, the vision of edge computing is to enable web se...
research
08/06/2019

WSEmail: A Retrospective on a System for Secure Internet Messaging Based on Web Services

Web services offer an opportunity to redesign a variety of older systems...
research
05/31/2019

Protocols for Checking Compromised Credentials

To prevent credential stuffing attacks, industry best practice now proac...
research
04/12/2021

Exploring the Attack Surface of WebSocket

Over the years, with the advancement of technology, Web technology has m...
research
06/06/2023

mdTLS: How to Make middlebox-aware TLS more efficient?

The more data transmission over TLS protocol becomes increasingly common...
research
04/14/2020

Gelato: Feedback-driven and Guided Security Analysis of Client-side Web Applications

Even though a lot of effort has been invested in analyzing client-side w...
research
06/21/2018

Oh, What a Fragile Web We Weave: Third-party Service Dependencies In Modern Webservices and Implications

The recent October 2016 DDoS attack on Dyn served as a wakeup call to th...

Please sign up or login with your details

Forgot password? Click here to reset