Designing secure session based on reverse proxy
Long Wen-guang, Jianping Li · 2012
Reverse proxy employs cookie as its ticket, so it can easily handle the user identification of enterprise. This paper discusses how to revise the transmitting cookie value of Reverse proxy and adjust it to the communication between background server and client entry, in order to maintain the effective cookie session between the client and the server. The paper analyzes the reason for the cookie is easy to attack, and works out a scheme of relaying the secure session, which covers the defect in protecting cookie.