Include Me Out: In-Browser Detection of Malicious Third-Party Content Inclusions

Include Me Out: In-Browser Detection of Malicious Third-Party Content Inclusions
复制标题

把我排除在外:恶意第三方内容包含的浏览器内检测

DOI:
--
复制
发表时间:
2016
期刊:
Financial Cryptography
影响因子:
--
通讯作者:
William K. Robertson
William K. Robertson
中科院分区:
--
文献类型:
--
作者:
Sajjad Arshad;Amin Kharraz;William K. Robertson

文献摘要

参考文献

被引文献

相似文献

现代网站包括各种类型的第三方内容,如JavaScript、图像、样式表和Flash对象,以创建交互式用户界面。除了网站发布者明确包含第三方内容之外,ISP和浏览器扩展正在越来越频繁地劫持Web浏览会话以注入第三方内容(例如,广告)。然而,第三方内容也可能给这些网站的用户带来安全风险,而网站运营商和用户都不知道。由于这些内含物通常具有高度动态的性质,以及在当代恶意软件中使用先进的伪装技术,因此在恶意第三方内容有机会攻击用户系统之前,抢先识别并阻止恶意第三方内容的内含物是非常困难的。
Modern websites include various types of third-party content such as JavaScript, images, stylesheets, and Flash objects in order to create interactive user interfaces. In addition to explicit inclusion of third-party content by website publishers, ISPs and browser extensions are hijacking web browsing sessions with increasing frequency to inject third-party content (e.g., ads). However, third-party content can also introduce security risks to users of these websites, unbeknownst to both website operators and users. Because of the often highly dynamic nature of these inclusions as well as the use of advanced cloaking techniques in contemporary malware, it is exceedingly difficult to preemptively recognize and block inclusions of malicious third-party content before it has the chance to attack the user’s system.
基于语言的不可信 JavaScript 隔离
DOI: 10.1109/csf.2009.11
发表时间: 2009
期刊: --
影响因子: --
作者:
Maffeis S
通讯作者: Maffeis S