科技报告详细信息
ACLs don't
Close, Tyler
HP Development Company
关键词: access control;    capability-based security;    Confused Deputy;    CSRF;    clickjacking;   
RP-ID  :  HPL-2009-20
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】

The ACL model is unable to make correct access decisions for interactions involving more than two principals, since required information is not retained across message sends. Though this deficiency has long been documented in the published literature, it is not widely understood. This logic error in the ACL model is exploited by both the clickjacking and Cross-Site Request Forgery attacks that affect many Web applications.

【 预 览 】
附件列表
Files Size Format View
RO201804100001452LZ 184KB PDF download
  文献评价指标  
  下载次数:11次 浏览次数:24次