JSON Web Tokens Lifecycle-Based Threat Classification

Iskander Zulkarneev, Konstantin A. Basalay · 2024

The paper discusses the security concepts of authentication and authorization systems that rely on JSON Web Tokens. It highlights the challenge of implementing access control, which is a common issue for many modern web applications. The paper also explores the benefits of using JSON Web Tokens in large information ecosystems. Also this article examines the structure of JSON Web Tokens and their vulnerabilities. Authors analyzed 139 CVE database vulnerabilities related to JWT-based authentication. The analysis revealed a tendency of growth in “Critical” and “High” vulnerability severity level, with a simultaneous decrease in “Medium” and “Low” levels. Additionally, undiscovered vulnerabilities were found. JSON Web Tokens lifecycle was examined on basis of vulnerability analysis. Vulnerabilities characteristic of each stage were identified. The discovered vulnerabilities were grouped according to the stages of the JSON Web Tokens lifecycle. A universal classification of JSON Web Tokens security threats is proposed based on its lifecycle. The classification includes the minimum necessary and sufficient parameters to describe all possible threats. It can be used in information system design, threat modelling, security assessment, incident investigation and testing of existing systems. Based on the proposed classification, it is possible to construct potential attack vectors on JSON Web Tokens authentication systems. This approach is expected to reduce the resources required to secure JWT-based systems.

Read the paper · More papers on PaperTik