Does this require the authentication cookie to be constant? If, for example, I issue a new cookie to the client every connection then this is mitigated?
Web applications that use HTTP Authentication cannot be fixed in this way, because you cannot change the password regularly. Other protocols that carry plain-text passwords (after SSL) may be even more vulnerable, for the same reason. For example, authenticated SMTP may be the worst case if the attacker can consistently force an automated client to reconnect and try again.
Or I could be very wrong about this. Please advise.
Not impossible, but not easy.