Man-in-the-browser Attack: A Case Study on Malicious Browser Extensions

dc.contributor.authorSampsa Rauti
dc.contributor.organizationfi=tietojenkäsittelytiede|en=Computer Science|
dc.contributor.organization-code1.2.246.10.2458963.20.23479734818
dc.converis.publication-id44603241
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/44603241
dc.date.accessioned2022-10-27T12:22:12Z
dc.date.available2022-10-27T12:22:12Z
dc.description.abstract<p>Man-in-the-browser (MitB) attacks, often implemented as malicious browser extensions, have the ability to alter the structure and contents of web pages, and stealthily change the data given by the user before it is sent to the server. This is done without the user or the online service (the server) noticing anything suspicious. In this study, we present a case study on the man-in-the-browser attack. Our proof-of-concept implementation demonstrates how easily this attack can be implemented as a malicious browser extension. The implementation is a UI-level, cross-browser implementation using JavaScript. We also successfully test the extension in a real online bank. By demonstrating a practical man-in-the-browser attack, our research highlights the need to better monitor and control malicious browser extensions.<br /></p>
dc.format.pagerange60
dc.format.pagerange71
dc.identifier.isbn978-981-15-4824-6
dc.identifier.issn1865-0929
dc.identifier.jour-issn1865-0929
dc.identifier.olddbid175044
dc.identifier.oldhandle10024/158138
dc.identifier.urihttps://www.utupub.fi/handle/11111/35386
dc.identifier.urnURN:NBN:fi-fe2021042823400
dc.language.isoen
dc.okm.affiliatedauthorRauti, Sampsa
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.relation.conferenceInternational Symposium on Security in Computing and Communication
dc.relation.doi10.1007/978-981-15-4825-3_5
dc.relation.ispartofjournalCommunications in Computer and Information Science
dc.relation.ispartofseriesCommunications in Computer and Information Science
dc.relation.volume1208
dc.source.identifierhttps://www.utupub.fi/handle/10024/158138
dc.titleMan-in-the-browser Attack: A Case Study on Malicious Browser Extensions
dc.title.bookSecurity in Computing and Communications: 7th International Symposium, SSCC 2019, Trivandrum, India, December 18–21, 2019, Revised Selected Papers
dc.year.issued2020

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
MitB_case.pdf
Size:
196.13 KB
Format:
Adobe Portable Document Format
Description:
Final draft