Enhancing the Security of Cookies
Vorapranee Khu-smith5
and Chris Mitchell5 
| (5) |
Information Security Group, Royal Holloway, University of London, TW20 0EX Egham, Surrey, UK |
Abstract
Cookies are pieces of information generated by a Web server to be stored in a user’s machine. The information in cookies can
range from selected items in a user’s shopping cart to authentication information used for accessing restricted pages. While
cookies are clearly very useful, they can also be abused. In this paper, security threats that cookies can pose to a user
are identified, as are the security requirements necessary to defeat them. Various options to meet the security requirements
are then examined. Proposed user-controlled approaches and their implementations are presented and compared with a server-controlled
approach, particularly the ‘Secure Cookies’ method, to illustrate the relative advantages and disadvantages of the two approaches.
Keywords Cookies - Internet security - Web security
References secured to subscribers.