Small files sent by the websites are known as Cookies that
need to be secured in order to prevent the information shared. The cookies
protected from the MiTM and having the attributes of security are known as the
secured cookies. However, such secured cookies have protection for the
confidentiality of the cookie but do not have the integrity protection. While
even the cookies having secure Attribute are given protection and Mallory
cannot read out them but still, there are chances that Mallory may rewrite and
make changes in the secured cookies (Garfinkel & Spafford, 2002). Other
attributes as Path attributes, HttpOnly, Domain, Cookie lifetime attributes can
also play actively in cookies protection.
While there is a need to prevent the Plain text HTTP from overwriting
and causing changes in the secure cookies.
References of Cookie Security
Garfinkel,
S., & Spafford, G. (2002). Web Security, Privacy & Commerce. O'Reilly
Media, Inc. Retrieved 12 1, 2018