Identifying Extension-Based Ad Injection via Fine-Grained Web Content Provenance

Identifying Extension-Based Ad Injection via Fine-Grained Web Content Provenance
复制标题

通过细粒度的 Web 内容来源识别基于扩展的广告注入

DOI:
--
复制
发表时间:
2016
期刊:
International Symposium on Recent Advances in Intrusion Detection
影响因子:
--
通讯作者:
William K. Robertson
William K. Robertson
中科院分区:
--
文献类型:
--
作者:
Sajjad Arshad;Amin Kharraz;William K. Robertson

文献摘要

被引文献

相似文献

扩展为web浏览器提供了有用的附加功能,但也是越来越流行的攻击载体。由于扩展可以拥有很高的权限,扩展被滥用来将广告注入网页,从而转移内容发布者的收入,并可能使用户暴露于恶意软件之下。用户通常不知道这种做法,认为对页面的修改来自发布者。此外,自动识别不需要的第三方修改从根本上来说是困难的,因为在没有恶意的情况下,用户是内容是否不需要的最终仲裁者。
Extensions provide useful additional functionality for web browsers, but are also an increasingly popular vector for attacks. Due to the high degree of privilege extensions can hold, extensions have been abused to inject advertisements into web pages that divert revenue from content publishers and potentially expose users to malware. Users are often unaware of such practices, believing the modifications to the page originate from publishers. Additionally, automated identification of unwanted third-party modifications is fundamentally difficult, as users are the ultimate arbiters of whether content is undesired in the absence of outright malice.