A Whitebox Analysis of Session Management and Account Creation in Web Applications

DSpace/Manakin Repository

Show simple item record

dc.contributor.advisor Calzavara, Stefano it_IT
dc.contributor.author Bozzolan, Simone <2000> it_IT
dc.date.accessioned 2024-06-04 it_IT
dc.date.accessioned 2024-11-13T09:45:58Z
dc.date.available 2024-11-13T09:45:58Z
dc.date.issued 2024-07-08 it_IT
dc.identifier.uri http://hdl.handle.net/10579/27222
dc.description.abstract Since the HTTP protocol is stateless by design, web applications have to implement client authentication by means of web sessions. Given the importance of client authentication, the web security community investigated session security at length. However, prior work in the field primarily focused on black-box testing, which has very limited access to the server-side logic of the web application. In this thesis, the first measurement of web session security based on static analysis of server-side code will be performed. From this distinctive vantage point, a number of security practices that cannot be assessed through black-box testing were analyzed, such as password hashing and cryptographic key management. This research analyzes more than 1,200 web applications built using the Django and Flask web development frameworks, unveiling a number of new insights on web session security that escaped prior work based on black-box testing. it_IT
dc.language.iso en it_IT
dc.publisher Università Ca' Foscari Venezia it_IT
dc.rights © Simone Bozzolan, 2024 it_IT
dc.title A Whitebox Analysis of Session Management and Account Creation in Web Applications it_IT
dc.title.alternative A Whitebox Analysis of Session Management and Account Creation in Web Applications it_IT
dc.type Master's Degree Thesis it_IT
dc.degree.name Computer science and information technology it_IT
dc.degree.level Laurea magistrale it_IT
dc.degree.grantor Dipartimento di Scienze Ambientali, Informatica e Statistica it_IT
dc.description.academicyear sessione_estiva_2023-2024_appello_08-07-24 it_IT
dc.rights.accessrights openAccess it_IT
dc.thesis.matricno 878352 it_IT
dc.subject.miur INF/01 INFORMATICA it_IT
dc.description.note it_IT
dc.degree.discipline it_IT
dc.contributor.co-advisor it_IT
dc.date.embargoend it_IT
dc.provenance.upload Simone Bozzolan (878352@stud.unive.it), 2024-06-04 it_IT
dc.provenance.plagiarycheck Stefano Calzavara (stefano.calzavara@unive.it), 2024-07-08 it_IT


Files in this item

This item appears in the following Collection(s)

Show simple item record