Detecting the Vulnerability of Multi-Party Authorization Protocols to Name Matching Attacks

semanticscholar(2014)

引用 0|浏览8
暂无评分
摘要
Software as a Service (SaaS) clouds cooperate to provide services, which often provoke multi-party authorization. The multi-party authorization suffers the so-called name matching attacks where involved parties misinterpret the other parties in the authorization, thus leading to undesired or even fatal consequences (e.g., an adversary can shop for free or can log into a victim’s Facebook account). In this paper, we propose a scheme to detect the vulnerability of multi-party authorization protocols that are susceptible to name matching attacks. We implement the detecting scheme and apply it to real world multi-party authorization protocols including Alipay PeerPay, Amazon FPS Marketplace, and PayPal Express Checkout. New name matching attacks are found, and fixes are proposed accordingly.
更多
查看译文
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要