Publication:
OVERSCAN: OAuth 2.0 Scanner for Missing Parameters

dc.contributor.authorKarin Sumongkayothinen_US
dc.contributor.authorPakpoom Rachtrachooen_US
dc.contributor.authorArnuphap Yupuechen_US
dc.contributor.authorKasidit Siripornen_US
dc.contributor.otherMahidol Universityen_US
dc.date.accessioned2020-01-27T08:22:55Z
dc.date.available2020-01-27T08:22:55Z
dc.date.issued2019-01-01en_US
dc.description.abstract© 2019, Springer Nature Switzerland AG. The websites are developed rapidly and wildly used by people around the world. The main reason is the increase of the immense number of internet users, which results in the security control of accessing sensitive information is necessary. The authorization server as the one security aspect which controls the access permission to the system. Many authentication protocols were proposed to meet these functional requirements. The open-standard authorization (OAuth) protocol is one of the well-known solutions widely used. However, many developers still misuse this protocol, which can cause security breaches. This paper proposes a tool named OVERSCAN, which is an OAuth2.0 scanner for misused or missing parameters. The experiments of using OVERSCAN have been conducted over 45 samples supporting OAuth2.0 protocol. The results show that 84.4% of samples lack significant parameters which can cause security problems.en_US
dc.identifier.citationLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). Vol.11928 LNCS, (2019), 221-233en_US
dc.identifier.doi10.1007/978-3-030-36938-5_13en_US
dc.identifier.issn16113349en_US
dc.identifier.issn03029743en_US
dc.identifier.other2-s2.0-85076990787en_US
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/50669
dc.rightsMahidol Universityen_US
dc.rights.holderSCOPUSen_US
dc.source.urihttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85076990787&origin=inwarden_US
dc.subjectComputer Scienceen_US
dc.subjectMathematicsen_US
dc.titleOVERSCAN: OAuth 2.0 Scanner for Missing Parametersen_US
dc.typeConference Paperen_US
dspace.entity.typePublication
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85076990787&origin=inwarden_US

Files

Collections