Systemuppdatering
På tisdag 18 augusti mellan kl. 12-13 kommer en planerad systemuppdatering av DiVA att ske. Under denna tid är DiVA inte tillgängligt.
Ändra sökning
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Security in Behaviour Driven Authentication for Web Applications
2012 (Engelska)Självständigt arbete på avancerad nivå (yrkesexamen), 20 poäng / 30 hpStudentuppsats (Examensarbete)
Abstract [en]

This paper describes the security research for a web application designed by BehavioSec. The application uses JavaScript to record keystrokes to generate data that is sent back to a server for verication. As this type of applications are often used in systems used for sensitive data, they are often targets for various attacks. The purpose of this paper is to decide what can be done to, if not prevent these attacks, then at least make it more dicult to succeed with an attack.Information has been gathered through web research, mainly based on the current programming languages that are being used in the application but alternatives has also been taken into consideration. Requests from BehavioSec has also been evaluated.There are many ways to increase the security around these kinds of applications. Web replay attacks could be countered by generating a JavaScript on the server side for each user that has the same functionality but with a dierent format each time. One way to prevent man in the browser attacks could be to use a verication based on the performed request from the client. Hashing the data could also help verify that the data has not been altered since it was transmitted from the client to some extent. To increase the security further a salt could be used with the hash function. No matter what solution is used, the use of sessions is recommended as it enable the possibility to store sensitive data on the server side instead of passing it to the client.

Ort, förlag, år, upplaga, sidor
2012. , s. 50
Nyckelord [en]
Technology
Nyckelord [sv]
Teknik
Identifikatorer
URN: urn:nbn:se:ltu:diva-47609Lokalt ID: 524774e5-6f23-419d-b157-6dc5205efee9OAI: oai:DiVA.org:ltu-47609DiVA, id: diva2:1020937
Ämne / kurs
Examensarbete, minst 30 hp
Utbildningsprogram
Civilingenjör, Datateknik
Handledare
Anmärkning
Validerat; 20120131 (anonymous)Tillgänglig från: 2016-10-04 Skapad: 2016-10-04 Senast uppdaterad: 2025-10-22Bibliografiskt granskad

Open Access i DiVA

fulltext(927 kB)1171 nedladdningar
Filinformation
Filnamn FULLTEXT02.pdfFilstorlek 927 kBChecksumma SHA-512
076bd650bef0c0ff470fec1a3cfb27926304d170811c9c0668a1c92389e99ebe86df84245b9dbf972618078a3799c65e26003fb9a92ca119c68949127642fbb2
Typ fulltextMimetyp application/pdf

Sök vidare i DiVA

Av författaren/redaktören
Nilsson, Daniel

Sök vidare utanför DiVA

GoogleGoogle Scholar
Totalt: 1171 nedladdningar
Antalet nedladdningar är summan av nedladdningar för alla fulltexter. Det kan inkludera t.ex tidigare versioner som nu inte längre är tillgängliga.

urn-nbn

Altmetricpoäng

urn-nbn
Totalt: 217 träffar
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf