Evaluation of an OAuth 2.0 Protocol Implementation for Web Server Applications

被引:0
|
作者
Darwish, Marwan [1 ]
Ouda, Abdelkader [1 ]
机构
[1] Univ Western Ontario, Dept Elect & Comp Engn, London, ON, Canada
关键词
OAuth; 2.0; protocol; web; server; applications;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
OAuth 2.0 is one of the protocols that are most commonly implemented as an authorization framework currently. This is because it has many advantages, one of which is its ability to be flexibly implemented on different systems and for different purposes. This work evaluates the implementation of Google's OAuth 2.0 for web server applications. This evaluation indicates that the implementation of Google's OAuth 2.0 protocol may lead to a security flaw that exploits low to medium size web servers. This threat might occur by exhausting the storage resources of the web server and making its applications unavailable. In addition, a number of recommendations are made to help protect against this type of threat when an OAuth 2.0 authorization protocol is implemented on web application servers.
引用
收藏
页数:4
相关论文
共 50 条
  • [31] Implementation of the Image Logging Server for Web Forensics
    Yoo, Seunghee
    Mun, Yilhyeong
    Cho, Dongsub
    2008 FIRST INTERNATIONAL CONFERENCE ON THE APPLICATIONS OF DIGITAL INFORMATION AND WEB TECHNOLOGIES, VOLS 1 AND 2, 2008, : 61 - 64
  • [32] Design and implementation of a web server for a hosting service
    Hara, Daisuke
    Ozaki, Ryota
    Hyoudou, Kazuki
    Nakayama, Yasuichi
    PROCEEDINGS OF THE NINTH IASTED INTERNATIONAL CONFERENCE ON INTERNET AND MULTIMEDIA SYSTEMS AND APPLICATIONS, 2005, : 69 - 74
  • [33] Remote Lab Implementation on an Embedded Web Server
    Alexander, P. J.
    Radhakrishnan, N.
    2015 INTERNATIONAL CONFERENCED ON CIRCUITS, POWER AND COMPUTING TECHNOLOGIES (ICCPCT-2015), 2015,
  • [34] The anisotropic network model web server at 2015 (ANM 2.0)
    Eyal, Eran
    Lum, Gengkon
    Bahar, Ivet
    BIOINFORMATICS, 2015, 31 (09) : 1487 - 1489
  • [35] MetaRanker 2.0: a web server for prioritization of genetic variation data
    Pers, Tune H.
    Dworzynski, Piotr
    Thomas, Cecilia Engel
    Lage, Kasper
    Brunak, Soren
    NUCLEIC ACIDS RESEARCH, 2013, 41 (W1) : W104 - W108
  • [36] Design and implementation of embedded Web server for LonWorks
    Wuhan University of Technology, Wuhan 430070, China
    不详
    Dianli Zidonghua Shebei Electr. Power Autom. Equip., 2007, 3 (77-80+85):
  • [37] Implementation and use of the PLT scheme Web server
    Krishnamurthi, Shriram
    Hopkins, Peter Walton
    McCarthy, Jay
    Graunke, Paul T.
    Pettyjohn, Greg
    Felleisen, Matthias
    Higher-Order and Symbolic Computation, 2007, 20 (04) : 431 - 460
  • [38] Implementation of load balancing in distributed Web server
    Wang, Jianqiu
    Zhang, Zhongneng
    Jisuanji Gongcheng/Computer Engineering, 2003, 29 (15):
  • [39] Developing web 2.0 applications for semantic web of trust
    Mahmood, Omer
    International Conference on Information Technology, Proceedings, 2007, : 819 - 824
  • [40] On the network effect in Web 2.0 applications
    Aggarwal, Charu C.
    Yu, Philip S.
    ELECTRONIC COMMERCE RESEARCH AND APPLICATIONS, 2012, 11 (02) : 142 - 151