Home > Research > Publications & Outputs > Failures of security APIs
View graph of relations

Failures of security APIs: a new case

Research output: Contribution in Book/Report/Proceedings - With ISBN/ISSNConference contribution/Paperpeer-review

Published
Publication date23/02/2016
Host publicationFinancial Cryptography and Data Security: 2016 Proceedings
Place of PublicationNew York
PublisherSpringer
Number of pages17
<mark>Original language</mark>English
EventFinancial Cryptography and Data Security 2016 - Accra Beach Hotel & Spa, Christ Church, Barbados
Duration: 22/02/201626/02/2016
http://fc16.ifca.ai/

Conference

ConferenceFinancial Cryptography and Data Security 2016
Country/TerritoryBarbados
CityChrist Church
Period22/02/1626/02/16
Internet address

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
ISSN (Print)0302-9743

Conference

ConferenceFinancial Cryptography and Data Security 2016
Country/TerritoryBarbados
CityChrist Church
Period22/02/1626/02/16
Internet address

Abstract

We report novel API attacks on a Captcha web service, and discuss lessons that we have learned. In so doing, we expand the horizon of security APIs research by extending it to a new setting. We also show that system architecture analysis is useful both for identifying vulnerabilities in security APIs and for fixing them.