Skip to content

Session Hijacking

What is Session Hijacking?

An attack in which an attacker takes over a valid user's web session by stealing or predicting the session token. Session hijacking gives the attacker the same privileges as the legitimate user.

Information Security

What the standards actually require on session hijacking

Requirements naming session hijacking across 2 standards, quoted from the control text.

Threats during the authentication event including replay attacks, man-in-the-middle, and session hijacking

29115-9.4 · Authentication mechanism threats

Operate cross-cutting requirements per NIST SP 800-63-3 / 63A / 63B / 63C. Threat Model per AAL: (a) per Section 8 of SP 800-63B + Section 4.4 of SP 800-63-3 (cover impersonation + verifier compromise + session hijacking + replay + phishing + denial of service...

NISTSP63-8 · Threat Model, Lifecycle Management, Privacy, Equity, Records, and Subscriber Communication

Questions people ask about session hijacking

What is Session Hijacking?
An attack in which an attacker takes over a valid user's web session by stealing or predicting the session token. Session hijacking gives the attacker the same privileges as the legitimate user.
Why is Session Hijacking important for compliance?
Session Hijacking is a key concept in Information Security. Understanding session hijacking helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Session Hijacking?
Session Hijacking appears in the requirement text of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework, NIST SP 800-63 Digital Identity Guidelines. Across these standards we have identified 2 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Session Hijacking?
Explore our compliance framework pages to see how session hijacking applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Session Hijacking applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.