首页> 外文会议>5th ACM symposium on information, computer and communications security 2009 >A Solution for the Automated Detection of Clickjacking Attacks
【24h】

A Solution for the Automated Detection of Clickjacking Attacks

机译:自动检测点击劫持攻击的解决方案

获取原文
获取原文并翻译 | 示例

摘要

Clickjacking is a web-based attack that has recently received a wide media coverage. In a clickjacking attack, a malicious page is constructed such that it tricks victims into clicking on an element of a different page that is only barely (or not at all) visible. By stealing the victim's clicks, an attacker could force the user to perform an unintended action that is advantageous for the attacker (e.g., initiate an online money transaction). Although clickjacking has been the subject of many discussions and alarming reports, it is currently unclear to what extent clickjacking is being used by attackers in the wild, and how significant the attack is for the security of Internet users.rnIn this paper, we propose a novel solution for the automated and efficient detection of clickjacking attacks. We describe the system that we designed, implemented and deployed to analyze over a million unique web pages. The experiments show that our approach is feasible in practice. Also, the empirical study that we conducted on a large number of popular websites suggests that clickjacking has not yet been largely adopted by attackers on the Internet.
机译:Clickjacking是一种基于Web的攻击,最近受到了广泛的媒体报道。在点击劫持攻击中,恶意页面的构建方式是诱使受害者单击仅勉强可见(或根本看不到)的其他页面的元素。通过窃取受害者的点击,攻击者可以迫使用户执行对攻击者有利的意外动作(例如,启动网上交易)。尽管点击劫持一直是许多讨论和令人震惊的报告的主题,但是目前尚不清楚攻击者在野外使用点击劫持的程度以及这种攻击对互联网用户的安全性有多重要。用于自动高效检测点击劫持攻击的新颖解决方案。我们描述了我们设计,实施和部署的系统,以分析超过一百万个唯一的网页。实验表明,我们的方法在实践中是可行的。另外,我们在大量流行网站上进行的经验研究表明,点击劫持尚未被互联网上的攻击者广泛采用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号