Threat Modeling for CSRF Attacks
Xiaoli Lin, Pavol Zavarsky, Ron Ruhl, Dale Lindskog · 2009
Cross-site request forgery (CSRF) vulnerability is extremely widespread and one of the top ten Web application vulnerabilities of the Open Web Application Security Project (OWASP). In this paper, we explore the CSRF vulnerabilities, illustrate the real-world CSRF attack, and present novel CSRF attack tree models. The threat models provide for exploring, understanding, and validating security protection features in realistic Web application scenarios.