Talk With an Expert

Authentication and Session Management on the Web

Authentication and Session Management on the Web (PDF, 2.36MB)Published: 28 Jan, 2005
Created by
Paul Johnston

This paper discusses how these requirements are met, primarily looking at how users are authenticated and login sessions maintained. We start by looking at the existing security measures for the basic website. Then we look at the various options for authenticating users in general, concluding that passwords are the only viable option. We look at options for implementing password authentication on the Web, and come to the 'session ID cookie' model used by many websites. Several attacks against such websites are demonstrated and various mitigation options are evaluated. We conclude with a summary of mitigations and a discussion of what is 'state of the art' in this area.