【24h】

An IDS for Browser Hijacking

机译:浏览器劫持的ID

获取原文

摘要

The steady evolution of browser tools and scripting languages has created a new, emergent threat to safe network operations: browser hijacking. In this type of attack, the user is not infected with regular malware but, while connected to a malicious or compromised website, front end languages such as javascript allow the user's browser to perform malicious activities; in fact, attackers usually operate within the scope of actions that a browser is expected to execute. Paradigmatic examples are the recent attacks on GitHub, where malicious javascript was injected into the browser of users accessing the search-giant Baidu, launching a devastating denial-of-service against a US-based company. Detecting this type of threat is particularly challenging, since the behavior of a browser is context specific. Detection can still be achieved, but to effectively hamper the effectiveness of this type of attack, users have to be empowered with appropriate detection tools, giving them the ability to autonomously detect and terminate suspicious types of browser behavior. This paper proposes such a tool. It uses information available within the browser (and is, thus, implementable as a browser extension), and it allows users to detect and terminate the suspicious types of behavior typical of hijacked browsers.
机译:浏览器工具和脚本语言的稳定演变为安全网络操作创造了一个新的,紧急的威胁:浏览器劫持。在这种类型的攻击中,用户没有被常规恶意软件感染,但是连接到恶意或受损的网站时,诸如JavaScript等前端语言允许用户的浏览器执行恶意活动;事实上,攻击者通常在浏览器预期执行的范围内运行。范式示例是最近对GitHub的攻击,其中恶意JavaScript被注入访问Search-Giant Baidu的用户的浏览器,这对针对美国的公司发起了毁灭性的拒绝服务。检测这种类型的威胁特别具有挑战性,因为浏览器的行为是特定的上下文。仍然可以实现检测,但要有效地妨碍这种类型的攻击的有效性,用户必须用适当的检测工具赋予用户,使其能够自主检测和终止可疑类型的浏览器行为。本文提出了这样的工具。它使用浏览器中可用的信息(因此,可实现为浏览器扩展名),并且它允许用户检测和终止典型的劫持浏览器的可疑类型的行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号