首页> 外文会议>International conference on cryptology and network security >Out of the Dark: UI Redressing and Trustworthy Events
【24h】

Out of the Dark: UI Redressing and Trustworthy Events

机译:走出黑暗:UI修复和值得信赖的事件

获取原文

摘要

Web applications use trustworthy events consciously triggered by a human user (e.g., a left mouse click) to authorize security-critical changes. Clickjacking and UI redressing (UIR) attacks trick the user into triggering a trustworthy event unconsciously. A formal model of Clickjacking was described by Huang et al. and was later adopted by the W3C UI safety specification. This formalization did not cover the target of these attacks, the trustworthy events. We provide the first extensive investigation on this topic and show that the concept is not completely understood in current browser implementations. We show major differences between widely-used browser families, even to the extent that the concept of trustworthy events itself becomes unrecognizable. We also show that the concept of trusted events as defined by the W3C is somehow orthogonal to trustworthy events, and may lead to confusion in understanding the security implications of both concepts. Based on these investigations, we were able to circumvent the concept of trusted events, introduce three new UIR attack variants, and minimize their visibility.
机译:Web应用程序使用由人类用户有意识地触发的可信赖事件(例如,鼠标左键单击)授权对安全性至关重要的更改。点击劫持和UI纠正(UIR)攻击会诱使用户无意识地触发可信赖的事件。 Huang等人描述了Clickjacking的正式模型。后来被W3C UI安全规范采用。这种形式化并未涵盖这些攻击的目标,可信赖的事件。我们提供了有关此主题的首次广泛研究,并显示了当前浏览器实现中尚未完全理解该概念。我们展示了广泛使用的浏览器系列之间的主要区别,甚至在可信任事件的概念本身变得不可识别的程度上。我们还表明,由W3C定义的可信事件的概念在某种程度上与可信事件正交,并且可能导致在理解这两个概念的安全性方面造成混淆。基于这些调查,我们能够绕过可信事件的概念,引入三种新的UIR攻击变体,并将其可见性降到最低。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号