Hardening the Security Analysis of Browser Extensions

被引:6
|
作者
Eriksson, Benjamin [1 ]
Picazo-Sanchez, Pablo [1 ]
Sabelfeld, Andrei [1 ]
机构
[1] Chalmers Univ Technol, Gothenburg, Sweden
基金
瑞典研究理事会;
关键词
Web Security; Browser Extensions;
D O I
10.1145/3477314.3507098
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Browser extensions boost the browsing experience by a range of features from automatic translation and grammar correction to password management, ad blocking, and remote desktops. Yet the power of extensions poses significant privacy and security challenges because extensions can be malicious and/or vulnerable. We observe that there are gaps in the previous work on analyzing the security of browser extensions and present a systematic study of attack entry points in the browser extension ecosystem. Our study reveals novel password stealing, traffic stealing, and inter-extension attacks. Based on a combination of static and dynamic analysis we show how to discover extension attacks, both known and novel ones, and study their prevalence in the wild. We show that 1,349 extensions are vulnerable to inter-extension attacks leading to XSS. Our empirical study uncovers a remarkable cluster of "New Tab" extensions where 4,410 extensions perform traffic stealing attacks. We suggest several avenues for the countermeasures against the uncovered attacks, ranging from refining the permission model to mitigating the attacks by declarations in manifest files.
引用
收藏
页码:1694 / 1703
页数:10
相关论文
共 50 条
  • [31] Detection of Inconsistencies in Privacy Practices of Browser Extensions
    Bui, Duc
    Tang, Brian
    Shin, Kang G.
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 2780 - 2798
  • [32] Stronger password authentication using browser extensions
    Ross, B
    Jackson, C
    Miyake, N
    Boneh, D
    Mitchell, JC
    USENIX Association Proceedings of the 14th USENIX Security Symposium, 2005, : 17 - 31
  • [33] Hulk: Eliciting Malicious Behavior in Browser Extensions
    Kapravelos, Alexandros
    Grier, Chris
    Chachra, Neha
    Kruegel, Christopher
    Vigna, Giovanni
    Paxson, Vern
    PROCEEDINGS OF THE 23RD USENIX SECURITY SYMPOSIUM, 2014, : 641 - 654
  • [34] Spying on the browser: Dissecting the design of malicious extensions
    Sood A.K.
    Enbody R.J.
    Network Security, 2011, 2011 (05) : 8 - 12
  • [35] Technical Perspective Making Browser Extensions Secure
    Kruegel, Christopher
    COMMUNICATIONS OF THE ACM, 2011, 54 (09) : 90 - 90
  • [36] Figure summarizer browser extensions for PubMed Central
    Agarwal, Shashank
    Yu, Hong
    BIOINFORMATICS, 2011, 27 (12) : 1723 - 1724
  • [37] Effective detection of vulnerable and malicious browser extensions
    Shahriar, Hossain
    Weldemariam, Komminist
    Zulkernine, Mohammad
    Lutellier, Thibaud
    COMPUTERS & SECURITY, 2014, 47 : 66 - 84
  • [38] EmPoWeb: Empowering Web Applications with Browser Extensions
    Some, Doliere Francis
    2019 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2019), 2019, : 227 - 245
  • [39] Extensible web browser security
    Ter Luow, Mike
    Lim, Jin Soon
    Venkatakrishnan, V. N.
    DETECTION OF INTRUSIONS AND MALWARE, AND VULNERABILITY ASSESSMENT, PROCEEDINGS, 2007, 4579 : 1 - +
  • [40] Hardening the Browser Protecting Patron Privacy on the Internet
    Phetteplace, Eric
    REFERENCE & USER SERVICES QUARTERLY, 2012, 51 (03) : 210 - 214