首页> 外文会议>International Symposium on Research in Attacks, Intrusions, and Defenses >Identifying Extension-Based Ad Injection via Fine-Grained Web Content Provenance
【24h】

Identifying Extension-Based Ad Injection via Fine-Grained Web Content Provenance

机译:通过细粒度的网上内容出处识别基于扩展的广告注射

获取原文

摘要

Extensions provide useful additional functionality for web browsers, but are also an increasingly popular vector for attacks. Due to the high degree of privilege extensions can hold, extensions have been abused to inject advertisements into web pages that divert revenue from content publishers and potentially expose users to malware. Users are often unaware of such practices, believing the modifications to the page originate from publishers. Additionally, automated identification of unwanted third-party modifications is fundamentally difficult, as users are the ultimate arbiters of whether content is undesired in the absence of outright malice. To resolve this dilemma, we present a fine-grained approach to tracking the provenance of web content at the level of individual DOM elements. In conjunction with visual indicators, provenance information can be used to reliably determine the source of content modifications, distinguishing publisher content from content that originates from third parties such as extensions. We describe a prototype implementation of the approach called ORIGINTRACER for Chromium, and evaluate its effectiveness, usability, and performance overhead through a user study and automated experiments. The results demonstrate a statistically significant improvement in the ability of users to identify unwanted third-party content such as injected ads with modest performance overhead.
机译:扩展为Web浏览器提供有用的附加功能,但也是攻击越来越流行的矢量。由于高度的特权扩展可以保持,扩展已被滥用,以将广告注入到从内容发布者转移收入的网页,并可能将用户暴露给恶意软件。用户通常不知道此类实践,相信对页面的修改源自发布商。此外,随着用户是在没有彻底恶意的情况下不希望的依据是不希望的,自动识别不需要的第三方修改的自动识别是根本困难的。为了解决这种困境,我们提出了一种细粒度的方法来跟踪网上内容的网上内容的出处。与视觉指示器结合使用,可以使用出处信息来可靠地确定内容修改的源,从源自扩展等第三方的内容中区分发布者内容。我们描述了一种称为铬的方法的原型实施,并通过用户学习和自动化实验评估其有效性,可用性和性能开销。结果表明,用户识别不需要的第三方内容,例如以适度的性能开销注入广告的能力的统计上显着改善。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号