VisibleV8: In-browser Monitoring of JavaScript in the Wild

VisibleV8: In-browser Monitoring of JavaScript in the Wild
复制标题

VisibleV8:浏览器内 JavaScript 监控

DOI:
10.1145/3355369.3355599
复制
发表时间:
2019
期刊:
Proceedings of the Internet Measurement Conference
影响因子:
--
通讯作者:
Kapravelos, Alexandros
Kapravelos, Alexandros
中科院分区:
--
文献类型:
--
作者:
Jueckstock, Jordan;Kapravelos, Alexandros

文献摘要

参考文献

被引文献

相似文献

现代网络安全和隐私研究依赖于对经常回避和敌对的网络的准确测量。现代网络不再仅仅是一个静态的、超链接的文档网络,而是充满了从可信度未知的第三方加载的JavaScript(JS)。动态分析潜在的恶意JS目前提出了一个残酷的困境:使用重量级的浏览器内解决方案,证明不可能维护,或使用轻量级的内联JS解决方案,可检测的规避JS和无法匹配的覆盖范围提供的浏览器系统。我们介绍了VisibleV8,一个托管在V8内部的动态分析框架,V8是Chrome浏览器的JS引擎,它在任何JS执行期间记录本机函数或属性访问。在不到600行(其中只有67修改V8的现有行为),我们的补丁是轻量级的,并已保持从Chrome版本63到72没有困难。VV8的性能始终优于同等的内联插装,它拦截了无法插装内联插装的访问。这个全面的覆盖范围使我们能够隔离和识别JS代码在野外使用的46个JavaScript命名空间工件,以检测自动浏览平台,并发现Alexa前50k站点中有29%加载了主动探测这些工件的内容。
Modern web security and privacy research depends on accurate measurement of an often evasive and hostile web. No longer just a network of static, hyperlinked documents, the modern web is alive with JavaScript (JS) loaded from third parties of unknown trustworthiness. Dynamic analysis of potentially hostile JS currently presents a cruel dilemma: use heavyweight in-browser solutions that prove impossible to maintain, or use lightweight inline JS solutions that are detectable by evasive JS and which cannot match the scope of coverage provided by in-browser systems. We present VisibleV8, a dynamic analysis framework hosted inside V8, the JS engine of the Chrome browser, that logs native function or property accesses during any JS execution. At less than 600 lines (only 67 of which modify V8's existing behavior), our patches are lightweight and have been maintained from Chrome versions 63 through 72 without difficulty. VV8 consistently outperforms equivalent inline instrumentation, and it intercepts accesses impossible to instrument inline. This comprehensive coverage allows us to isolate and identify 46 JavaScript namespace artifacts used by JS code in the wild to detect automated browsing platforms and to discover that 29% of the Alexa top 50k sites load content which actively probes these artifacts.
Web 代码重用攻击:通过脚本小工具打破跨站点脚本缓解措施
DOI: 10.1145/3133956.3134091
发表时间: 2017
期刊: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Sebastian Lekies;Krzysztof Kotowicz;Samuel Groß;E. Nava;Martin Johns
通讯作者: Martin Johns
DOI: 10.1145/2810103.2813656
发表时间: 2015-10
期刊: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Christopher Neasbitt;Bo Li;R. Perdisci;Long Lu;Kapil Singh;Kang Li
通讯作者: Christopher Neasbitt;Bo Li;R. Perdisci;Long Lu;Kapil Singh;Kang Li
DOI: 10.1109/eurosp.2017.26
发表时间: 2017-04
期刊: 2017 IEEE European Symposium on Security and Privacy (EuroS&P)
影响因子: --
作者:
Georg Merzdovnik;Markus Huber;D. Buhov;Nick Nikiforakis;S. Neuner;Martin Schmiedecker;E. Weippl
通讯作者: Georg Merzdovnik;Markus Huber;D. Buhov;Nick Nikiforakis;S. Neuner;Martin Schmiedecker;E. Weippl
Fp-Scanner:浏览器指纹不一致的隐私影响
DOI: --
发表时间: 2018
期刊: USENIX Security Symposium
影响因子: --
作者:
Antoine Vastel;Pierre Laperdrix;Walter Rudametkin;Romain Rouvoy
通讯作者: Romain Rouvoy
DOI: 10.1145/2420950.2420952
发表时间: 2012-12
期刊: --
影响因子: --
作者:
Pieter Agten;S. Acker;Yoran Brondsema;Phu H. Phung;Lieven Desmet;Frank Piessens
通讯作者: Pieter Agten;S. Acker;Yoran Brondsema;Phu H. Phung;Lieven Desmet;Frank Piessens