首页> 外文会议>2014 IEEE 28th International Conference on Advanced Information Networking and Applications Workshops >Protection against Web 2.0 Client-Side Web Attacks Using Information Flow Control
【24h】

Protection against Web 2.0 Client-Side Web Attacks Using Information Flow Control

机译:使用信息流控制防范Web 2.0客户端Web攻击

获取原文
获取原文并翻译 | 示例

摘要

The dynamic nature of the Web 2.0 and the heavy obfuscation of web-based attacks complicate the job of the traditional protection systems such as Firewalls, Anti-virus solutions, and IDS systems. It has been witnessed that using ready-made toolkits, cyber-criminals can launch sophisticated attacks such as cross-site scripting (XSS), cross-site request forgery (CSRF) and botnets to name a few. In recent years, cyber-criminals have targeted legitimate websites and social networks to inject malicious scripts that compromise the security of the visitors of such websites. This involves performing actions using the victim browser without his/her permission. This poses the need to develop effective mechanisms for protecting against Web 2.0 attacks that mainly target the end-user. In this paper, we address the above challenges from information flow control perspective by developing a framework that restricts the flow of information on the client-side to legitimate channels. The proposed model tracks sensitive information flow and prevents information leakage from happening. The proposed model when applied to the context of client-side web-based attacks is expected to provide a more secure browsing environment for the end-user.
机译:Web 2.0的动态性质以及对基于Web的攻击的沉重迷惑使诸如防火墙,防病毒解决方案和IDS系统之类的传统保护系统的工作复杂化。目击者证明,使用现成的工具包,网络犯罪分子可以发起复杂的攻击,例如跨站点脚本(XSS),跨站点请求伪造(CSRF)和僵尸网络等。近年来,网络犯罪分子已将合法网站和社交网络作为攻击目标,以注入恶意脚本,这些脚本损害了此类网站的访问者的安全。这涉及在未经受害者浏览器允许的情况下使用受害者浏览器执行操作。这就需要开发有效的机制来防御主要针对最终用户的Web 2.0攻击。在本文中,我们从信息流控制的角度出发,通过开发一个框架来解决上述挑战,该框架将客户端的信息流限制为合法的渠道。所提出的模型跟踪敏感的信息流并防止信息泄漏的发生。所建议的模型应用于基于Web的客户端攻击的上下文时,有望为最终用户提供更安全的浏览环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号