Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments

Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments
复制标题

DOI:
10.1109/sp46214.2022.9833753
复制
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Mohammad Ghasemisharif;Chris Kanich;Jason Polakis
Mohammad Ghasemisharif;Chris Kanich;Jason Polakis
中科院分区:
其他
文献类型:
--
作者:
Mohammad Ghasemisharif;Chris Kanich;Jason Polakis

文献摘要

相似文献

单点登录(SSO)是现代Web上用户身份验证和授权的核心和关键组件,因为它通常由Web和移动应用程序与基于凭据的身份验证一起提供,以促进帐户创建和登录过程。然而,本地帐户管理和后台SSO功能之间的相互作用会导致启用或放大帐户劫持攻击的漏洞。这些缺陷并不存在于实际的SSO协议中,但由于支持单独但混合的身份验证路径的复杂性而显露出来。因此,这些类型的缺陷不能被先前工作中提出的单点登录协议或实现验证工具检测到。在本文中,我们介绍了SAAT,这是一个全自动化的模块化框架,它评估使用Facebook作为IdP的依赖方(RP)是否遵守安全实践和指导方针,并揭示源于SSO和本地功能的相互作用或受其影响的帐户和会话管理中的缺陷。我们对Facebook的RPS中的身份验证和会话实践进行了大规模的探索,揭示了一个不稳定的生态系统,其中SSO支持可能会突然被放弃,17.6%的测试RPS展示了不起作用的SSO实现。这突出表明有必要通过SAAT对SSO生态系统进行持续和系统的测试。更严重的是,我们发现安全措施经常缺失,官方指南经常被忽视或配置错误,只有0.8%的RP完全启用了重新身份验证,这可以防止被劫持的身份提供商(IDP)Cookie的危害。我们的研究还显示,只有不到2%的RP正确地对SSO撤销做出反应,67%的RP在撤销后10天仍继续允许帐户访问。总体而言,我们将我们的框架设想为一种工具,用于支持和指导主要SSO身份提供商的广泛补救努力,而这在以前是不可行的,因为这个生态系统的巨大规模和固有的易变性。
Single Sign-On (SSO) is both a core and critical component of user authentication and authorization on the modern web, as it is often offered by web and mobile applications alongside credential-based authentication to facilitate the account creation and login process. However, the interplay between local account management and SSO functionality in the backend leads to flaws that enable or magnify account hijacking attacks. These flaws are not baked into the actual SSO protocols, but manifest due to the complexity of supporting separate but intermingling authentication paths. As a result, these types of flaws cannot be detected by the SSO protocol or implementation verification tools proposed in prior work. In this paper we introduce SAAT, a fully automated modular framework that assesses whether relying parties (RPs) that use Facebook as the IdP comply with secure practices and guidelines, and uncovers flaws in account and session management that stem from or are affected by the interplay of SSO and local functionality. We conduct a large-scale exploration of authentication and session practices in Facebook’s RPs, revealing a volatile ecosystem where SSO support can be suddenly dropped and 17.6% of the tested RPs exhibit non-functional SSO implementations. This highlights the need for the continuous and systematic testing of the SSO ecosystem made possible by SAAT. More critically, we find that security measures are often missing and official guidelines are routinely overlooked or misconfigured, with only 0.8% of the RPs fully enabling re-authentication which can prevent compromise from hijacked identity provider (IdP) cookies. Our study also shows that less than 2% of RPs correctly react to SSO revocation and 67% continue to allow account access even 10 days after revocation. Overall, we envision our framework as a tool for enabling and guiding widespread remediation efforts by major SSO identity providers, which were previously infeasible due to the sheer scale and inherent mutability of this ecosystem.