CSRF Attack Mechanism and Defense Strategy
Youling Gong · Information Security and Communications Privacy · 2014
Cross-site request forgery is a widespread network attack on the Internet. Through request forgery by the third party,this attack deceives the server,passes itself off as the user and exercises the rights of the users. This paper describes the characteristics of CSRF and analyzes the principle of CSRF. And meanwhile simulation on the attack process and exploration on the cause of this attack are also done,and the defense strategies against this attack discussed from both server and client sides.