Proceedings of the International scientific and practical conference ―Oxford 2026: Science and Education Today‖ (May 29-31, 2026) / Publisher website: www.naukainfo.com. - Oxford, United Kingdom, 2026. - 392 p.

185 UDC 004.056.54 Kamianskyi Yaroslav ORCID ID: 0009-0000-5035-6441 Lavro Maksim Humeniuk Ivan Honcharuk Ilya Stoliar Mykhailo 2nd year cadets Scientific advisor: Kaliakin Serhii senior lecturer, Department of Counteracting Cybercrime Kharkiv National University of Internal Affairs ORCID ID: 0000-0003-3946-0189 SESSION HIJACKING AND REAL-TIME PROXYATTACKS Abstract. The threat of session hijacking and AiTM attacks through real-time proxy servers is considered. The bypass of traditional MFA is analyzed and the need for the use of FIDO2/ WebAuthn hardware keys, UEBA systems, and Zero architecture is justified. Trust for effective protection. Keywords: session hijacking, multi-factor authentication, service token, cyber threats, ZeroTrust architecture . In today's digital world, user authentication in web applications and corporate networks is largely based on session tokens. Compromising such a token allows an attacker to take full control of a victim's account without needing to know their password. Of particular concern are attacks carried out in real time using proxy servers, which allow attackers to bypass multi-factor authentication (MFA). According to Microsoft Digital Defense Report 2024, the number of AiTM attacks increased by

RkJQdWJsaXNoZXIy MTAxMzIwNA==