Efficient System to Prevent Session Hijacking Attack on Servers using Proxy Server

Anuradha Maurya · International Journal for Research in Applied Science and Engineering Technology · 2021

HTTP is a stateless protocol thus we tend to use cookie to maintain session.For maintaining a session server creates a unique identifier to remember on going session for particular client.This distinctive identifier is nothing but a randomly generated text which is stored on client browser in the form of cookie.These cookies are generally created in the login process, after successful authentication process, server generates unique id for requested client and send it to client.Browser sends this cookie on every request where authentication of user is required.Authentication of cookie become temporary replacement of user password authentication for the entire session.Cookies are static in nature, they do not change in the session life time, because of this nature anyone can steal and use this cookie for their benefit.Use of cookies introduces a number of risks in security especially in session authentication.For secure communication use of HTTPS is not easy for those applications that are highly distributed due to performance and financial issues and HTTPS provide security at network only there are many ways were attacker can steal cookie by using different attack like cross site scripting attack, cross site tracing attack, domain related attack etc.Hence, creating a system using Concept of one-time dynamic cookie (OTDC) for authentication instead of HTTPS. OTDC will prevent various attacks on servers. A reverse proxy server with OTDC, IP Address, session ID and browser fingerprinting are used to prevent opponent from capturing session credentials. Setting up HTTPS to HTTP Reverse Proxy Server, Session time out implementation on Proxy server because "The less time you give your account to be cracked, the better for you." Generating log on attack detection and reporting to administrator. Keywords: prevention of session

Read the paper · More papers on PaperTik