首页> 外文会议>Symposium on Chemistry as a second language >A Solution for the Automated Detection of Clickjacking Attacks
【24h】

A Solution for the Automated Detection of Clickjacking Attacks

机译:ClickJacking攻击自动检测的解决方案

获取原文

摘要

Clickjacking is a web-based attack that has recently received a wide media coverage. In a clickjacking attack, a malicious page is constructed such that it tricks victims into clicking on an element of a different page that is only barely (or not at all) visible. By stealing the victim's clicks, an attacker could force the user to perform an unintended action that is advantageous for the attacker (e.g., initiate an online money transaction). Although clickjacking has been the subject of many discussions and alarming reports, it is currently unclear to what extent clickjacking is being used by attackers in the wild, and how significant the attack is for the security of Internet users. In this paper, we propose a novel solution for the auto mated and efficient detection of clickjacking attacks. We describe the system that we designed, implemented and de ployed to analyze over a million unique web pages. The experiments show that our approach is feasible in practice. Also, the empirical study that we conducted on a large num ber of popular websites suggests that clickjacking has not yet been largely adopted by attackers on the Internet.
机译:ClickJacking是一个基于Web的攻击,最近收到了广泛的媒体覆盖范围。在ClickJacking攻击中,构建了一种恶意页面,使得它欺骗受害者单击仅仅只能可见的不同页面的元素。通过窃取受害者的点击次数,攻击者可以强迫用户执行对攻击者有利的意外操作(例如,启动在线货币交易)。虽然ClickJacking一直是许多讨论和警报报告的主题,但目前目前不清楚野外攻击者在多大程度上使用攻击者,以及攻击的互联网安全性有多重要。在本文中,我们提出了一种新颖的解决方案,用于自动交配和有效地检测ClickJacking攻击。我们描述了我们设计,实施和de的系统,以分析超过一百万个独特的网页。实验表明,我们的方法在实践中是可行的。此外,我们在大量流行的网站上进行的实证研究表明,互联网上的攻击者尚未通过基本采用ClickJacking。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号