Preventing Session Hijacking using Encrypted One-Time-Cookies

Renascence Tarafder Prapty, Shuhana Azmin, Md. Shohrab Hossain, Husnu S. Narman · 2020

Hypertext Transfer Protocol (HTTP) cookies are pieces of information shared between HTTP server and client to remember stateful information for the stateless HTTP protocol or to record a user's browsing activity. Cookies are often used in web applications to identify a user and corresponding authenticated session. Thus, stealing a cookie can lead to hijacking an authenticated user's session. To prevent this type of attack, a cookie protection mechanism is required. In this paper, we have proposed a secure and efficient cookie protection system. We have used one time cookies to prevent attacker from performing cookie injection. To ensure cookie integrity and confidentiality, we have encrypted sensitive information in the cookie. We have verified that our proposed system can ensure confidentiality, authenticity and integrity through security analysis. Our proposed system can efficiently prevent session hijacking performed through replay attack and cookie poisoning attack.

Read the paper · More papers on PaperTik