首页> 外文会议>IEEE Conference on Communications and Network Security >Analyzing the dangers posed by Chrome extensions
【24h】

Analyzing the dangers posed by Chrome extensions

机译:分析Chrome扩展程序带来的危险

获取原文

摘要

A common characteristic of modern web browsers is that their functionality can be extended via third-party add-ons. In this paper we focus on Chrome extensions, to which the Chrome browser exports a rich API: extensions can potentially make network requests, access the local file system, get low-level information about running processes, etc. To guard against misuse, Chrome uses a permission system to curtail an extension's privileges. We demonstrate a series of attacks by which extensions can steal data, track user behavior, and collude to elevate their privileges. Although some attacks have previously been reported, we show that subtler versions can easily be devised that are less likely to be prevented by proposed defenses and can evade notice by the user. We quantify the potential danger of attacks by examining how many currently available extensions have sufficient privileges to carry them out. As many web sites do not employ defenses against such attacks, we examine how many popular web sites are vulnerable to each kind of attack. Our results show that a surprisingly large fraction of web sites is vulnerable to many attacks, and a large fraction of currently available extensions is potentially able to carry them out.
机译:现代网络浏览器的一个共同特征是可以通过第三方插件扩展其功能。在本文中,我们重点介绍Chrome扩展程序,Chrome浏览器将向其中导出丰富的API:这些扩展程序可能会发出网络请求,访问本地文件系统,获取有关正在运行的进程的低级信息等。为防止滥用,Chrome会使用限制扩展权限的权限系统。我们演示了一系列攻击,扩展可以通过这些攻击窃取数据,跟踪用户行为并合谋提升其特权。尽管以前已经报道了一些攻击,但我们表明,可以轻松设计更巧妙的版本,而不太可能被提议的防御措施阻止,并且可以逃避用户的注意。我们通过检查当前有多少扩展具有足够的特权来执行攻击,从而量化了攻击的潜在危险。由于许多网站没有针对此类攻击采取防御措施,因此我们检查了多少种流行的网站易受每种攻击的影响。我们的结果表明,令人惊讶的是,很大一部分网站都容易受到许多攻击,并且当前可用扩展中的很大一部分都可以将它们实施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号