Welcome to the full schedule of the OWASP AppSec Research EU 2013 conference days. You’ll find the schedule for the training days at http://trainings2013.appsec.eu
Thursday, August 22 • 5:35pm - 6:20pm
A Doorman for Your Home - Control-Flow Integrity Means in Web Frameworks

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Modern web applications frequently implement complex control flows, which require the users to perform actions in a given order. Users interact with a web application by sending HTTP requests with parameters and in response receive web pages with hyperlinks that indicate the expected next actions. If a web application takes for granted that the user sends only those expected requests and parameters, malicious users can exploit this assumption by crafting harming requests. We analyze recent attacks on web applications with respect to user-defined requests and identify their root cause in the missing explicit control-flow definition and enforcement. Then, we evaluate the most prevalent web application frameworks in order to assess possibly existing means to explicitly define and enforce intended control flows. While we find that all tested frameworks allow individual retrofit solutions, only one out of ten provides a dedicated control-flow integrity protection feature. Finally, we describe ways to equip web applications with control-flow integrity properties.

avatar for Bastian Braun

Bastian Braun

Bastian Braun received a diploma in computer science (with honors) and a bachelor degree in economics from RWTH Aachen in 2006. Afterwards, he joined the research group "Security in Distributed Systems" at the University of Hamburg. In 2008, he moved to the University of Passau where... Read More →

Thursday August 22, 2013 5:35pm - 6:20pm CEST