Failures of security APIs: a new case

Abdalnaser Algwil, Jeff Yan*

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution book

Abstract

We report novel API attacks on a Captcha web service, and discuss lessons that we have learned. In so doing, we expand the horizon of security APIs research by extending it to a new setting. We also show that system architecture analysis is useful both for identifying vulnerabilities in security APIs and for fixing them.

Original languageEnglish
Title of host publicationFinancial Cryptography and Data Security
Subtitle of host publication20th International Conference, FC 2016, Christ Church, Barbados, February 22–26, 2016, Revised Selected Papers
EditorsJens Grossklags, Bart Preneel
Place of PublicationCham, Switzerland
PublisherSpringer
Pages283-298
Number of pages16
ISBN (Print)9783662549698
DOIs
Publication statusPublished - 17 May 2017
Event20th International Conference on Financial Cryptography and Data Security, FC 2016 - Christ Church, Barbados
Duration: 22 Feb 201626 Feb 2016

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume9603 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference20th International Conference on Financial Cryptography and Data Security, FC 2016
Country/TerritoryBarbados
CityChrist Church
Period22/02/1626/02/16

Keywords

  • API attacks
  • architecture analysis for security
  • CAPTCHA
  • web security

Fingerprint

Dive into the research topics of 'Failures of security APIs: a new case'. Together they form a unique fingerprint.

Cite this