PCSRF: A Personalized CSRF Simulation Framework for Security Education and Attack Delivery Analysis


Ozturk A. C., Malkawi M., ALHAJJ R.

34th IEEE International Requirements Engineering Conference Workshops, REW 2026, Montreal, Kanada, 17 - 21 Ağustos 2026, ss.170-175, (Tam Metin Bildiri)

  • Yayın Türü: Bildiri / Tam Metin Bildiri
  • Doi Numarası: 10.1109/rew72749.2026.00034
  • Basıldığı Şehir: Montreal
  • Basıldığı Ülke: Kanada
  • Sayfa Sayıları: ss.170-175
  • Anahtar Kelimeler: attack simulation, cross-site request forgery (csrf), personalization, security education
  • İstanbul Medipol Üniversitesi Adresli: Evet

Özet

Cross-Site Request Forgery (CSRF) demonstrations often focus on the forged request itself, while giving less attention to the user-facing context that leads a user toward the triggering interaction. This paper presents PCSRF, short for Personalized Cross-Site Request Forgery, a controlled simulation environment for demonstrating personalized CSRF attack delivery. The system we present combines a legitimate local web application, a separate malicious site, and a simulated fake mail inbox that generates lure messages from lightweight email-derived signals. In the workflow we propose, the user first authenticates with the legitimate application. After login, the fake inbox uses either the active session email or a test email passed through a query parameter. The personalization module normalizes and parses the input email address, extracts domain, role, and optional personalike signals, and selects a template family through configurable scoring criteria. When the user clicks on the generated button, the interaction is routed to the malicious site. This is where the hidden CSRF request is submitted to the legitimate application while the session is still active. Sample test cases show that different email identities lead to different lure families while preserving the same observable CSRF attack path. The results demonstrate that personalized delivery can be modeled using transparent scoring rules, while leaving real email delivery, external profile collection, and AI-generated lure content as possible extensions. By separating fake-inbox delivery from CSRF execution, PCSRF makes the delivery stage of CSRF attacks easier to inspect, reproduce, and extend for educational and experimental use.