...
首页> 外文期刊>Mobile Computing, IEEE Transactions on >An Empirical Evaluation of Security Indicators in Mobile Web Browsers
【24h】

An Empirical Evaluation of Security Indicators in Mobile Web Browsers

机译:移动Web浏览器中安全性指标的实证评估

获取原文
获取原文并翻译 | 示例
           

摘要

Mobile browsers are increasingly being relied upon to perform security sensitive operations. Like their desktop counterparts, these applications can enable SSL/TLS to provide strong security guarantees for communications over the web. However, the drastic reduction in screen size and the accompanying reorganization of screen real-estate significantly changes the use and consistency of the security indicators and certificate information that alert users of site identity and the presence of strong cryptographic algorithms. In this paper, we perform the first measurement of the state of critical security indicators in mobile browsers. We evaluate ten mobile and two tablet browsers, representing over 90% of the market share, against the recommended guidelines for web user interface to convey security set forth by the World Wide Web Consortium (W3C). While desktop browsers follow the majority of guidelines, our analysis shows that mobile browsers fall significantly short. We also observe notable inconsistencies across mobile browsers when such mechanisms actually are implemented. We show where and how these failures on mobile browsers eliminate clues previously designed for, and still present in, desktop browsers to detect attacks such as phishing and man-in-the-middle. Finally, we offer advice on where current standards are unclear or incomplete.
机译:越来越多地依赖移动浏览器来执行安全敏感的操作。像台式机一样,这些应用程序可以使SSL / TLS为Web上的通信提供强大的安全保证。但是,屏幕尺寸的急剧减小以及随之而来的屏幕房地产的重组,极大地改变了安全指示符和证书信息的使用和一致性,这些安全性指示符和证书信息向用户发出站点标识和强大密码算法的警报。在本文中,我们对移动浏览器中的关键安全指标的状态进行了首次测量。我们根据万维网联盟(W3C)提出的建议来指导Web用户界面以传达安全性的准则,评估了十个移动浏览器和两个平板浏览器,它们占据了90%以上的市场份额。尽管台式机浏览器遵循大多数准则,但我们的分析表明,移动浏览器明显不足。当实际实现这种机制时,我们还会观察到跨移动浏览器的显着不一致。我们将展示这些故障在移动浏览器上的位置和方式,以及如何消除以前为台式机浏览器设计并仍然存在的线索,以检测网络钓鱼和中间人等攻击。最后,我们针对目前尚不清楚或不完整的标准提供建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号