Secure Model For Session Hijacking using Hashing Algorithm
Nidhi Thakkar, Rajvirsinh Vaghela · International journal of advance research and innovative ideas in education · 2018
Session Hijacking is one of the most used attacks by the attacker. Session Hijacking is the second most attack as per the OWASP latest release in the year of 2017. It is the most crucial attack through which attacker can gain the access of the client’s running session. In Session Hijacking attacker steals the session id of the victim and with the use of that session id attacker can able to access the current session. In this time, the session is being secured with the use of SSL or TLS. There are few drawbacks and less security of the SSL. Here a new approach is proposed to face the issue of Session Hijacking attack. The system is specially designed to address the issue of session hijacking in local network. The proposed system is using the MAC address and client’s id and generates the session id with MD5 algorithm. MD5 algorithm is providing the 128 bits session id. At the time of request Server will authenticate the user bases on Session Id as well as MAC address of the system. In case of successful session key theft, attacker will not be able to access the session as the MAC is also required to access the session. To make it more secure and reduces the chances of MAC spoofing, the use of ARP protocol can be restricted in the network. The proposed system is best solution for attack of Session Hijacking in the local network. After successful implementation the system will provide the security against this type of attack.