Security Analysis of Attack Surfaces on the Grant Negotiation and Authorization Protocol

dc.contributor.authorAxeland, Åke
dc.contributor.authorOueidat, Omar
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.examinerClaessen, Koen
dc.contributor.supervisorPicazo-Sanchez, Pablo
dc.date.accessioned2021-09-10T07:48:53Z
dc.date.available2021-09-10T07:48:53Z
dc.date.issued2021sv
dc.date.submitted2020
dc.description.abstractAccessibility is a booming practice, with applications incorporating easy authentication and authorization increasing. OAuth 2.0 is a framework created to easily integrate resourceful platforms with a client application, giving users the opportunity to access their resources in different means while only storing them in one place. Due to resources often being confidential or private the security of such frameworks is imperative. GNAP is a new protocol inspired by OAuth 2.0, created with the intention to uphold security standards of modern application usage. This thesis tests GNAP and its robustness against legacy attacks targeting OAuth 2.0. The tests consist of vulnerable redirect URI attacks, access code hijacking, CSRF, and AS mix-up attacks. Results show that due to GNAP’s cryptographic-based design, attacks that utilize data manipulation or additional input are not possible in the environment created for the thesis. However, given the less secured client instance in the protocol, AS mix-up attacks are possible in a niche environment given the assumptions made in the thesis.sv
dc.identifier.urihttps://hdl.handle.net/20.500.12380/304105
dc.language.isoengsv
dc.setspec.uppsokTechnology
dc.subjectOAuth 2.0sv
dc.subjectOAuth 2.1sv
dc.subjectGNAPsv
dc.subjectauthenticationsv
dc.subjectauthorizationsv
dc.subjectsecuritysv
dc.titleSecurity Analysis of Attack Surfaces on the Grant Negotiation and Authorization Protocolsv
dc.type.degreeExamensarbete för masterexamensv
dc.type.uppsokH
Ladda ner
Original bundle
Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 21-100 Oueidat Axeland.pdf
Storlek:
1.47 MB
Format:
Adobe Portable Document Format
Beskrivning:
License bundle
Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
1.51 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: