Web Hack List

Collected research

AUTHSCAN: Automatic Extraction of Web Authentication Protocols from Implementations

AUTHSCAN records browser HTTP traces and JavaScript execution, then infers an authentication protocol spec in an intermediate language (TML) via dynamic symbolic analysis plus blackbox differential fuzzing. The spec becomes applied pi-calculus checked by ProVerif and counterexamples are replayed to confirm attacks. It found 7 flaws in BrowserID, Facebook Connect, Windows Live ID and two sites.

Record

Researcher
Guangdong Bai, Jike Lei, Guozhu Meng, Sai Sathyanarayan Venkatraman, Prateek Saxena, Jun Sun, Yang Liu and Jin Song Dong
Published by
NDSS Symposium
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Guangdong Bai, Jike Lei, Guozhu Meng, Sai Sathyanarayan Venkatraman, Prateek Saxena, Jun Sun, Yang Liu and Jin Song Dong, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .