Detecting Spying and Fraud Browser Extensions: Short Paper

G. Varshney, M. Misra, P. Atrey
{"title":"Detecting Spying and Fraud Browser Extensions: Short Paper","authors":"G. Varshney, M. Misra, P. Atrey","doi":"10.1145/3137616.3137619","DOIUrl":null,"url":null,"abstract":"Due to the flaws in policy followed by web browsers for granting permissions to browser extensions and due to a lack of effective static and dynamic detection systems for identifying malicious extensions uploaded on the web stores, malicious browser extensions have become the easiest way to carry out phishing, spying, fraud and other kinds of advanced attacks. This paper identifies and analyzes a subset of these attacks which can be performed with the use of malicious browser extensions (using Google Chrome) and discusses the research gaps of the existing prevention and detection schemes to adequately defend against these attacks. An initial set of malicious signatures responsible for cyber fraud and spying is identified during the study. We use this set of signatures to develop a lightweight malicious extension detection system which can alert users of suspected spying or fraud extensions installed on the Chrome browser on a PC. Results show that the proposed detection system performs better than known malicious extension detectors such as Chrome Cleanup tool and Chrome safeguard tool.","PeriodicalId":198787,"journal":{"name":"Proceedings of the 2017 on Multimedia Privacy and Security","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-10-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2017 on Multimedia Privacy and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3137616.3137619","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Due to the flaws in policy followed by web browsers for granting permissions to browser extensions and due to a lack of effective static and dynamic detection systems for identifying malicious extensions uploaded on the web stores, malicious browser extensions have become the easiest way to carry out phishing, spying, fraud and other kinds of advanced attacks. This paper identifies and analyzes a subset of these attacks which can be performed with the use of malicious browser extensions (using Google Chrome) and discusses the research gaps of the existing prevention and detection schemes to adequately defend against these attacks. An initial set of malicious signatures responsible for cyber fraud and spying is identified during the study. We use this set of signatures to develop a lightweight malicious extension detection system which can alert users of suspected spying or fraud extensions installed on the Chrome browser on a PC. Results show that the proposed detection system performs better than known malicious extension detectors such as Chrome Cleanup tool and Chrome safeguard tool.
检测间谍和欺诈浏览器扩展:短论文
由于web浏览器授予浏览器扩展权限的策略存在缺陷,并且由于缺乏有效的静态和动态检测系统来识别上传到web商店的恶意扩展,恶意浏览器扩展已成为进行网络钓鱼,间谍,欺诈和其他类型高级攻击的最简单方法。本文识别并分析了这些攻击的一个子集,这些攻击可以通过使用恶意浏览器扩展(使用谷歌Chrome)来执行,并讨论了现有预防和检测方案的研究差距,以充分防御这些攻击。在研究期间,确定了一组负责网络欺诈和间谍活动的初始恶意签名。我们使用这组签名来开发一个轻量级的恶意扩展检测系统,该系统可以提醒用户在PC上安装在Chrome浏览器上的可疑间谍或欺诈扩展。结果表明,该检测系统的性能优于已知的恶意扩展检测工具,如Chrome Cleanup工具和Chrome safeguard工具。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信