Session Hijacking
What is Session Hijacking?
An attack in which an attacker takes over a valid user's web session by stealing or predicting the session token. Session hijacking gives the attacker the same privileges as the legitimate user.
Frameworks that govern session hijacking
What the standards actually require on session hijacking
Requirements naming session hijacking across 2 standards, quoted from the control text.
Threats during the authentication event including replay attacks, man-in-the-middle, and session hijacking
29115-9.4 · Authentication mechanism threats →Operate cross-cutting requirements per NIST SP 800-63-3 / 63A / 63B / 63C. Threat Model per AAL: (a) per Section 8 of SP 800-63B + Section 4.4 of SP 800-63-3 (cover impersonation + verifier compromise + session hijacking + replay + phishing + denial of service...
NISTSP63-8 · Threat Model, Lifecycle Management, Privacy, Equity, Records, and Subscriber Communication →Questions people ask about session hijacking
What is Session Hijacking?
Why is Session Hijacking important for compliance?
Which compliance frameworks address Session Hijacking?
Where can I learn more about Session Hijacking?
See how Session Hijacking applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.