首页> 外文会议>International conference on information and communications security >Defeat Information Leakage from Browser Extensions via Data Obfuscation
【24h】

Defeat Information Leakage from Browser Extensions via Data Obfuscation

机译:通过数据混淆消除浏览器扩展中的信息泄漏

获取原文

摘要

Today web browsers have become the de facto platform for Internet users. This makes browsers the target of a lot of attacks. With the security considerations from the very beginning, Chrome offers more protection against exploits via benign-but-buggy extensions. However, more and more attacks have been launched via malicious extensions while there is no effective solution to defeat such malicious extensions. As user's sensitive information is often the target of such attacks, in this paper, we aim to proactively defeat information leakage with our iObfus framework. With iObfus, sensitive information is always classified and labeled automatically. Then sensitive information is obfuscated before any 10 operation is conducted. In this way, the users' sensitive information is always protected even information leakage occurs. The obfuscated information is properly restored for legitimate browser transactions. A prototype has been implemented and iObfus works seamlessly with the Chromium 25. Evaluation against malicious extensions shows the effectiveness of iObfus, while it only introduces trivial overhead to benign extensions.
机译:今天,Web浏览器已经成为Internet用户事实上的平台。这使浏览器成为许多攻击的目标。从一开始就出于安全考虑,Chrome会通过良性但精简的扩展程序为攻击提供更多保护。但是,通过恶意扩展发起了越来越多的攻击,而没有有效的方法来击败此类恶意扩展。由于用户的敏感信息通常是此类攻击的目标,因此在本文中,我们旨在通过iObfus框架主动消除信息泄漏。使用iObfus,总是可以对敏感信息进行自动分类和标记。然后对敏感信息进行混淆,然后再执行10次操作。这样,即使发生信息泄漏,也始终可以保护用户的敏感信息。对于合法的浏览器事务,已正确处理了被混淆的信息。已经实现了一个原型,并且iObfus与Chromium 25无缝协作。针对恶意扩展的评估显示了iObfus的有效性,而它仅对良性扩展造成了微不足道的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号