Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

Evaluation of Cryptographically Secure Pseudo-Random Generated CRSF Encrypted Synchronizer Token Patterns

DJS Sako , HO Wodi & VT Emmah :

Abstract

Cross-Site Request Forgery (CSRF) attacks pose a significant security threat by exploiting trust in authenticated user sessions, allowing unauthorized actions to be performed on behalf of users without their consent. In this work, we proposed a high entropy encrypted Synchronizer Token Pattern (eSTP), which uses server-generated and encrypted, session-specific, unique, highly unpredictable token tied to the user's session to validate requests. To be secure against brute- force attacks, tokens need to have sufficient randomness. We simulated the process of generation, encryption and decryption of the CSRF tokens and evaluated the performance of the system by its security and cryptographic strength of the CSRF tokens by measuring the level of randomness and unpredictability (entropy) of the generated and encrypted tokens for different sizes of cryptographically secure pseudorandom number generators and session key lengths. Results show sufficient randomness for all the generated tokens with corresponding increase in entropy values for the encrypted tokens; an indication that encrypted tokens have sufficient length (entropy) to prevent brute-force attacks.

Keywords

Cross-Site Request Forgerytokenscryptographyvulnerability

References

Agrawal, S. (2023). Mitigating Cross-Site Request Forgery (CSRF) Attacks Using Reinforcement Learning and Predictive Analytics. Applied Research in Artificial Intelligence and Cloud Computing, 6(9), 17–30. Retrieved on 20-Jul-2025 from https://researchberg.com/index.php/araic/article/view/189 Alharbi, S., & Malaiya, Y. K. (2018). A survey of cross-site request forgery defense mechanisms. In Proceedings of 11th International Conference of IEEE on Developments in eSystems Engineering (DeSE), 37-42 Aljawarneh, S., Alomari, O., Aldwairi, M., &Fraiwan, L. (2020). Cross-Site Request Forgery (CSRF) Attacks: Current Trends, Challenges, and Future Directions. IEEE Access, 8, 190785-190797. Alsaleh, M., & Kaur, H. (2020). Survey on CSRF attack and defense mechanisms. Journal of Network and Computer Applications, 156, 102634. Baldanzi, L., Crocetti, L., Falaschi, F., Bertolucci, M., Belli, J., Fanucci, L., & Saponara, S. (2020). Cryptographically Secure Pseudo-Random Number Generator IP-Core Based on SHA2 Algorithm. Sensors, 20(7), 1869. https://doi.org/10.3390/s20071869 Bang, J., Kim, J. N., & Lee, S. (2024). Entropy Sharing in Ransomware: Bypassing Entropy-Based Detection of Cryptographic Operations. Sensors, 24(5), https://doi.org/10.3390/s24051446 Biswas, J., Hasan, M., Saiful, Md., Mim, F.T., and Tasnim, N. (2025). A Review on Mitigating Security Risks: Effective Strategies to Prevent Cross-Site Request Forgery Vulnerabilities Brown, A., Smith, B., & Johnson, C. (2017). Enhancing Security in Social Media Platforms: A Case Study of Automated CSRF Protection. International Journal of Information Security, 16(5), 479-493. De Ryck, P., Desmet, L., Joosen, W. & Piessens, F. (2011). Automatic and Precise Client-Side Protection against CSRF Attacks. 6879. 100-116. 10.1007/978-3-642-23822-2_6. Dizdar, A. (2025). What is a CSRF Token and How Does It Work? Accessed on 17-jul-2025 from https://brightsec.com/blog/csrf-token/ Garcia, F. D., Uceda-Sosa, R., &Laorden, C. (2018). A review on cross-site request forgery. Journal of Network and Computer Applications, 118, 76-89. Hasan, F. and Anderson, R. (2024). Prevent Cross-Site Request Forgery (XSRF/CSRF) attacks in ASP.NET Core. https://learn.microsoft.com/en-us/aspnet/core/security/anti-request- forgery?view=aspnetcore-9.0. Accessed on 12-Jul-2025. Irfan, M. & Khan, M.A.( 2025). Cryptographically Secure Pseudo-Random Number Generation (CS-PRNG) Design using Robust Chaotic Tent Map (RCTM). Cogent Engineering, 12(1). https://doi.org/10.1080/23311916.2025.2558751 Karaca, Y and Moonis, M. (2022). Shannon entropy-based complexity quantification of nonlinear stochastic process: diagnostic and predictive spatiotemporal uncertainty of multiple sclerosis subgroups, Editor(s): Yeliz Karaca, Dumitru Baleanu, Yu-Dong Zhang, Osvaldo Gervasi, Majaz Moonis, Multi-Chaos, Fractal and Multi-Fractional Artificial Intelligence of Different Complex Systems, Academic Press. Kirsten, S. (n.d). Cross-Site Request Forgery (CSRF). Retrieved on 12-Jul-2025 from https://owasp.org/www-community/attacks/csrf Kombade, R. D., & Meshram, B. (2018). CSRF Vulnerabilities and Defensive Techniques. International Journal of Computer Network and Information Security (IJCNIS), 4, 31. Likaj, X., Khodayari, S and Pellegrino, G. (2021). Where We Stand (or Fall): An Analysis of CSRF Defenses in Web Frameworks. In 24th ACM International Symposium on Research in Attacks, Intrusions and Defenses (RAID ’21), San Sebastian, Spain, 16. https://doi.org/10.1145/nnnnnnn.nnnnnnn Luengo, EA and Villaizán, JR (2023). Cryptographically Secured Pseudo-Random Number Generators: Analysis and Testing with NIST Statistical Test Suite. Mathematics. 11(23), 4812; https://doi.org/10.3390/math11234812 Melosik, M., Galan, M., Naumowicz, M., Tylczy?ski, P. and Koziol, S. (2023). Cryptographically Secure PseudoRandom Bit Generator for Wearable Technolog, Entropy, 25(7), 976; https://doi.org/10.3390/e25070976 Muhenga, R., Sapundzhi, F., Popstoilov, M., Georgiev, S., & Todorov, V. (2025). Comprehensive Analysis of Cryptographic Algorithms: Implementation and Security Insights. Engineering Proceedings, 104(1), 43. https://doi.org/10.3390/engproc2025104043 National Vulnerability Database (n.d.). National Vulnerability Database: CSRF statistics. https://nvd.nist.gov/vuln/search/statistics?form_type=Advanced&results_type=statistics& query=CSRF&search_type=all. OWASP. (2016). Open Web Application Security Project., OWASP, Top Ten. https://owasp.org/www-project-top-ten/. Patgiri, R. (2021). privateDH: An Enhanced Diffie-Hellman Key-Exchange Protocol using RSA and AES Algorithms, IACR Cryptology, https://eprint.iacr.org/2021/647.pdf Patil, P., Narayankar, P., Narayan, D.G.& Meena, S.M.(2016). A Comprehensive Evaluation of Cryptographic Algorithms: DES, 3DES, AES, RSA and Blowfish. ScienceDirect, Elsevier,78, 617 – 624 Puoli, F. Pittorino, F., and Roveri, M. (2024). Quantifying Cryptocurrency Unpredictability: A Comprehensive Study of Complexity and Forecasting. Proceedings of the 4th International Conference on AI-ML Systems, 6, 1-8. https://doi.org/10.1145/3703412.370342 Randunu, D. (2019). CSRF Synchronizer Token Pattern. https://medium.com/@ridmadinu1/csrf- synchronizer-token-pattern-766f36ea0c62. Accessed 12-Jun-2025 Robinson, D. W. (2008). Entropy and Uncertainty. Entropy, 10(4), 493-506. https://doi.org/10.3390/e10040493 Vajapeyam, S. (2014). Understanding Shannon's Entropy metric for Information. Accessed 12-Jul-2025 from https://arxiv.org/pdf/1405.2061 Williams, B, Hiromoto, RE and Carlson, A. (2023). Analysis of a Cryptographically Secure Pseudo- Random Number Generator, IEEE 12th International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS), Dortmund, Germany, 259-264, doi: 10.1109/IDAACS58523.2023.10348766. Yadda, LF (2025). Shannon Entropy, Its Calculation and Role in LLM Transformer Token Processing, Accessed on 13-July-2025 https://lfyadda.com/shannon-entropy-its- calculation-and-role-in-llm-transformer-token-processing/ Zareen, H., Haq, M. A., Aziz, Z., & Nazir, M. (2020). Cross-Site Request Forgery (CSRF) Attack: A Comprehensive Survey, Recent Trends, and Future Directions. IEEE Access, 8, 117469- 117487.

More Articles from INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND MATHEMATICAL THEORY

Advances in Algorithmic Contract Scoring for Pre-Negotiation Yield Optimization and Risk Retention

Author: Ngozi Samuel Uzougbo, Michael Ominyi, Cyril Chimelie Anichukwueze, Blessing, Chika Jones

DevTest flow: Designing a Scalable Continuous Testing Pipeline for High-Velocity Software Delivery

Author: Lawal Ahmed Oladimeji, Achori Busayo, Akeju BusayoZainab, Saka Samson, Damilare, Mbah Demian Chidi, Runsewe Similoluwa Mayowa, Oladiti Luqman, Abiodun