首页> 外文会议>International conference on information systems security >VulnerableMe: Measuring Systemic Weaknesses in Mobile Browser Security
【24h】

VulnerableMe: Measuring Systemic Weaknesses in Mobile Browser Security

机译:VulnerableMe:测量移动浏览器安全性中的系统缺陷

获取原文

摘要

Porting browsers to mobile platforms may lead to new vulnerabilities whose solutions require careful balancing between usability and security and might not always be equivalent to those in desktop browsers. In this paper, we perform the first large-scale security comparison between mobile and desktop browsers. We focus our efforts on display security given the inherent screen limitations of mobile phones. We evaluate display elements in ten mobile, three tablet and five desktop browsers. We identify two new classes of vulnerabilities specific to mobile browsers and demonstrate their risk by launching real-world attacks including display ballooning, login CSRF and clickjacking. Additionally, we implement a new phishing attack that exploits a default policy in mobile browsers. These previously unknown vulnerabilities have been confirmed by browser vendors. Our observations, inputs from browser vendors and the pervasive nature of the discovered vulnerabilities illustrate that new implementation errors leading to serious attacks are introduced when browser software is ported from the desktop to mobile environment. We conclude that usability considerations are crucial while designing mobile solutions and display security in mobile browsers is not comparable to that in desktop browsers.
机译:将浏览器移植到移动平台可能会导致新的漏洞,其解决方案需要在可用性和安全性之间进行仔细平衡,并且可能并不总是等同于台式机浏览器中的漏洞。在本文中,我们执行了移动浏览器和桌面浏览器之间的首次大规模安全性比较。鉴于手机固有的屏幕局限性,我们将精力集中在显示安全上。我们评估了十个移动设备,三个平板电脑和五个桌面浏览器中的显示元素。我们确定了针对移动浏览器的两类新漏洞,并通过发起包括显示气球,登录CSRF和点击劫持的真实攻击来证明其风险。此外,我们实施了一种新的网络钓鱼攻击,该攻击利用了移动浏览器中的默认策略。这些以前未知的漏洞已由浏览器供应商确认。我们的观察,来自浏览器供应商的投入以及发现的漏洞的普遍性质表明,当将浏览器软件从台式机移植到移动环境时,会引入导致严重攻击的新实现错误。我们得出结论,在设计移动解决方案时,可用性考虑至关重要,并且移动浏览器中的显示安全性无法与台式机浏览器中的显示安全性相提并论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号