Browser extension-based man-in-the-browser attacks against Ajax applications with countermeasures

dc.contributor.authorSampsa Rauti
dc.contributor.authorVille Leppänen
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.converis.publication-id3091546
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/3091546
dc.date.accessioned2022-10-28T12:39:20Z
dc.date.available2022-10-28T12:39:20Z
dc.description.abstractAs the web pages today rely on Ajax and JavaScript, a larger attack surface becomes available. This paper presents in detail several different man-in-the-browser attacks against Ajax applications. We implemented browser extensions for Mozilla Firefox to demonstrate these attacks and their effectiveness. Some countermeasures to mitigate the problem are also considered. We conclude that man-in-the-browser attacks are a serious threat to online applications and there are only partial countermeasures to alleviate the problem.
dc.format.pagerange251
dc.format.pagerange258
dc.identifier.isbn978-1-4503-1193-9
dc.identifier.olddbid178002
dc.identifier.oldhandle10024/161096
dc.identifier.urihttps://www.utupub.fi/handle/11111/49828
dc.identifier.urnURN:NBN:fi-fe2021042715039
dc.language.isoen
dc.okm.affiliatedauthorRauti, Sampsa
dc.okm.affiliatedauthorLeppänen, Ville
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.publisher.countryUnited Statesen_GB
dc.publisher.countryYhdysvallat (USA)fi_FI
dc.publisher.country-codeUS
dc.publisher.placeNew York, NY
dc.relation.conferenceInternational Conference on Computer Systems and Technologies
dc.relation.doi10.1145/2383276.2383314
dc.source.identifierhttps://www.utupub.fi/handle/10024/161096
dc.titleBrowser extension-based man-in-the-browser attacks against Ajax applications with countermeasures
dc.title.bookCompSysTech '12: Proceedings of the 13th International Conference on Computer Systems and Technologies
dc.year.issued2012

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
mitb.pdf
Size:
131.66 KB
Format:
Adobe Portable Document Format
Description:
Final draft