Design of Session Security Module for Web Applications

Shiyi Xie · Jisuanji gongcheng · 2008

This paper analyzes the main menace of session security, and describes the basic principle and method of session hijacking. A secure session module based on HTTP is designed for repelling session hijacking attack. The module adds a hashed MAC to session IDs, and monitors incoming requests and outgoing responses for session ID cookies. It makes it difficult for attacker to reuse the sessions ID cookie and gives Web applications well protected. It achieves the secure session module based on the .net platform, and the module is used on an e-business Web site.

Read the paper · More papers on PaperTik