{"id":"https://openalex.org/W4288057702","doi":"https://doi.org/10.1109/sp46214.2022.9833753","title":"Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments","display_name":"Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments","publication_year":2022,"publication_date":"2022-05-01","ids":{"openalex":"https://openalex.org/W4288057702","doi":"https://doi.org/10.1109/sp46214.2022.9833753"},"language":"en","primary_location":{"id":"doi:10.1109/sp46214.2022.9833753","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833753","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"type":"conference-paper","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5045937628","display_name":"Mohammad Ghasemisharif","orcid":"https://orcid.org/0009-0002-8710-7742"},"institutions":[{"id":"https://openalex.org/I39422238","display_name":"University of Illinois Chicago","ror":"https://ror.org/02mpq6x41","country_code":"US","type":"education","lineage":["https://openalex.org/I39422238"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mohammad Ghasemisharif","raw_affiliation_strings":["University of Illinois at Chicago"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Illinois at Chicago","institution_ids":["https://openalex.org/I39422238"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070578895","display_name":"Chris Kanich","orcid":"https://orcid.org/0000-0002-3836-2168"},"institutions":[{"id":"https://openalex.org/I39422238","display_name":"University of Illinois Chicago","ror":"https://ror.org/02mpq6x41","country_code":"US","type":"education","lineage":["https://openalex.org/I39422238"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chris Kanich","raw_affiliation_strings":["University of Illinois at Chicago"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Illinois at Chicago","institution_ids":["https://openalex.org/I39422238"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5018209439","display_name":"Jason Polakis","orcid":"https://orcid.org/0000-0001-5034-0730"},"institutions":[{"id":"https://openalex.org/I39422238","display_name":"University of Illinois Chicago","ror":"https://ror.org/02mpq6x41","country_code":"US","type":"education","lineage":["https://openalex.org/I39422238"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jason Polakis","raw_affiliation_strings":["University of Illinois at Chicago"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Illinois at Chicago","institution_ids":["https://openalex.org/I39422238"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I39422238"],"apc_list":null,"apc_paid":null,"fwci":4.5223,"has_fulltext":false,"cited_by_count":22,"citation_normalized_percentile":{"value":0.95911346,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1774","last_page":"1790"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9957000017166138,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/single-sign-on","display_name":"Single sign-on","score":0.8263247609138489},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7971919775009155},{"id":"https://openalex.org/keywords/authentication","display_name":"Authentication (law)","score":0.7376345992088318},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.7253268957138062},{"id":"https://openalex.org/keywords/credential","display_name":"Credential","score":0.6572284698486328},{"id":"https://openalex.org/keywords/session","display_name":"Session (web analytics)","score":0.6545344591140747},{"id":"https://openalex.org/keywords/login","display_name":"Login","score":0.5952820777893066},{"id":"https://openalex.org/keywords/audit","display_name":"Audit","score":0.43029043078422546},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.3687790334224701},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.09703266620635986}],"concepts":[{"id":"https://openalex.org/C2776362682","wikidata":"https://www.wikidata.org/wiki/Q568494","display_name":"Single sign-on","level":3,"score":0.8263247609138489},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7971919775009155},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.7376345992088318},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7253268957138062},{"id":"https://openalex.org/C2777810591","wikidata":"https://www.wikidata.org/wiki/Q16861606","display_name":"Credential","level":2,"score":0.6572284698486328},{"id":"https://openalex.org/C2779182362","wikidata":"https://www.wikidata.org/wiki/Q17126187","display_name":"Session (web analytics)","level":2,"score":0.6545344591140747},{"id":"https://openalex.org/C113324615","wikidata":"https://www.wikidata.org/wiki/Q472302","display_name":"Login","level":2,"score":0.5952820777893066},{"id":"https://openalex.org/C199521495","wikidata":"https://www.wikidata.org/wiki/Q181487","display_name":"Audit","level":2,"score":0.43029043078422546},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.3687790334224701},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.09703266620635986},{"id":"https://openalex.org/C121955636","wikidata":"https://www.wikidata.org/wiki/Q4116214","display_name":"Accounting","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/sp46214.2022.9833753","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833753","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":38,"referenced_works":["https://openalex.org/W88388190","https://openalex.org/W1197495329","https://openalex.org/W1425767035","https://openalex.org/W1851665508","https://openalex.org/W2089775132","https://openalex.org/W2108272360","https://openalex.org/W2133723082","https://openalex.org/W2217843339","https://openalex.org/W2399231848","https://openalex.org/W2400427673","https://openalex.org/W2463495559","https://openalex.org/W2509745758","https://openalex.org/W2510134782","https://openalex.org/W2536255411","https://openalex.org/W2575458798","https://openalex.org/W2725419186","https://openalex.org/W2733681384","https://openalex.org/W2766473095","https://openalex.org/W2794584163","https://openalex.org/W2889521075","https://openalex.org/W2931478288","https://openalex.org/W2962768977","https://openalex.org/W2968483187","https://openalex.org/W2969671680","https://openalex.org/W2972981608","https://openalex.org/W3007024382","https://openalex.org/W3107473573","https://openalex.org/W3130650850","https://openalex.org/W3153326528","https://openalex.org/W3153466684","https://openalex.org/W3172367785","https://openalex.org/W6639067945","https://openalex.org/W6688448285","https://openalex.org/W6712739088","https://openalex.org/W6719104381","https://openalex.org/W6740744476","https://openalex.org/W6754808855","https://openalex.org/W6767100559"],"related_works":["https://openalex.org/W2392755385","https://openalex.org/W2364108391","https://openalex.org/W2490563716","https://openalex.org/W2185800392","https://openalex.org/W4319777932","https://openalex.org/W4387766710","https://openalex.org/W2082874810","https://openalex.org/W812360551","https://openalex.org/W3031028275","https://openalex.org/W1607245420"],"abstract_inverted_index":{"Single":[0],"Sign-On":[1],"(SSO)":[2],"is":[3,21],"both":[4],"a":[5,87,114,161,173,281],"core":[6],"and":[7,13,26,37,47,135,137,142,156,166,183,200,221,263,285,304],"critical":[8],"component":[9],"of":[10,79,91,154,164,185,203,232,256,307],"user":[11],"authentication":[12,31,84,165],"authorization":[14],"on":[15],"the":[16,34,41,51,69,77,97,129,152,186,195,198,204,233,301],"modern":[17],"web,":[18],"as":[19,128,280],"it":[20],"often":[22,219],"offered":[23],"by":[24,96,151,209,290],"web":[25],"mobile":[27],"applications":[28],"alongside":[29],"credential-based":[30],"to":[32,54,76,260,266,300],"facilitate":[33],"account":[35,45,60,141,268],"creation":[36],"login":[38],"process.":[39],"However,":[40],"interplay":[42,153],"between":[43],"local":[44,157],"management":[46,144],"SSO":[48,71,98,155,177,191,205,261,292],"functionality":[49],"in":[50,105,140,169],"backend":[52],"leads":[53],"flaws":[55,64,92,139],"that":[56,119,125,145,215,252],"enable":[57],"or":[58,100,148,227],"magnify":[59],"hijacking":[61],"attacks.":[62],"These":[63],"are":[65,149,218,224],"not":[66],"baked":[67],"into":[68],"actual":[70],"protocols,":[72],"but":[73,82],"manifest":[74],"due":[75,299],"complexity":[78],"supporting":[80],"separate":[81],"intermingling":[83],"paths.":[85],"As":[86],"result,":[88],"these":[89],"types":[90],"cannot":[93],"be":[94,180],"detected":[95],"protocol":[99],"implementation":[101],"verification":[102],"tools":[103],"proposed":[104],"prior":[106],"work.":[107],"In":[108],"this":[109,308],"paper":[110],"we":[111,213,276],"introduce":[112],"SAAT,":[113],"fully":[115,235],"automated":[116],"modular":[117],"framework":[118,279],"assesses":[120],"whether":[121],"relying":[122],"parties":[123],"(RPs)":[124],"use":[126],"Facebook":[127],"IdP":[130],"comply":[131],"with":[132,229],"secure":[133],"practices":[134,168],"guidelines,":[136],"uncovers":[138],"session":[143,167],"stem":[146],"from":[147,242],"affected":[150],"functionality.":[158],"We":[159],"conduct":[160],"large-scale":[162],"exploration":[163],"Facebook\u2019s":[170],"RPs,":[171],"revealing":[172],"volatile":[174],"ecosystem":[175,206],"where":[176],"support":[178],"can":[179,239],"suddenly":[181],"dropped":[182],"17.6%":[184],"tested":[187],"RPs":[188,234,257],"exhibit":[189],"non-functional":[190],"implementations.":[192],"This":[193],"highlights":[194],"need":[196],"for":[197,283],"continuous":[199],"systematic":[201],"testing":[202],"made":[207],"possible":[208],"SAAT.":[210],"More":[211],"critically,":[212],"find":[214],"security":[216],"measures":[217],"missing":[220],"official":[222],"guidelines":[223],"routinely":[225],"overlooked":[226],"misconfigured,":[228],"only":[230],"0.8%":[231],"enabling":[236,284],"re-authentication":[237],"which":[238,295],"prevent":[240],"compromise":[241],"hijacked":[243],"identity":[244,293],"provider":[245],"(IdP)":[246],"cookies.":[247],"Our":[248],"study":[249],"also":[250],"shows":[251],"less":[253],"than":[254],"2%":[255],"correctly":[258],"react":[259],"revocation":[262],"67%":[264],"continue":[265],"allow":[267],"access":[269],"even":[270],"10":[271],"days":[272],"after":[273],"revocation.":[274],"Overall,":[275],"envision":[277],"our":[278],"tool":[282],"guiding":[286],"widespread":[287],"remediation":[288],"efforts":[289],"major":[291],"providers,":[294],"were":[296],"previously":[297],"infeasible":[298],"sheer":[302],"scale":[303],"inherent":[305],"mutability":[306],"ecosystem.":[309]},"counts_by_year":[{"year":2026,"cited_by_count":4},{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":8},{"year":2022,"cited_by_count":2}],"updated_date":"2026-07-29T14:22:42.915294","created_date":"2025-10-10T00:00:00"}
