Security Busters: Web browser security vs. rogue sites

نویسندگان

  • Nikos Virvilis
  • Alexios Mylonas
  • Nikolaos Tsalis
  • Dimitris Gritzalis
چکیده

URL blacklists are used by the majority of modern web browsers as a means to protect users from rogue web sites, i.e. those serving malware and/or hosting phishing scams. There is a plethora of URL blacklists/reputation services, out of which Google’s Safe Browsing and Microsoft’s SmartScreen stand out as the two most commonly used ones. Frequently, such lists are the only safeguard web browsers implement against such threats. Inevitably, as with any blacklist implementation, there is a time window between the creation of a rogue web site and the time it gets submitted to the blacklist(s), in which users are not protected. In this paper, we examine the level of protection that is offered by popular web browsers on iOS, Android and desktop (Windows) platforms, against a large set of phishing and malware URL. The results reveal that most browsers – especially those for mobile devices offer limited protection against such threats. As a result, we propose and evaluate an architecture, which can be used to significantly improve the level of protection offered to the users, regardless of the web browser or platform they are using.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A First Look at the CT Landscape: Certificate Transparency Logs in Practice

Many of today’s web-based services rely heavily on secure end-to-end connections. The “trust” that these services require builds upon TLS/SSL. Unfortunately, TLS/SSL is highly vulnerable to compromised Certificate Authorities (CAs) and the certificates they generate. Certificate Transparency (CT) provides a way to monitor and audit certificates and certificate chains, to help improve the overal...

متن کامل

Better Security and Privacy for Web Browsers: A Survey of Techniques, and a New Implementation

The web browser is one of the most security critical software components today. It is used to interact with a variety of important applications and services, including social networking services, e-mail services, and e-commerce and e-health applications. But the same browser is also used to visit less trustworthy sites, and it is unreasonable to make it the end-user’s responsibility to “browse ...

متن کامل

Improving the Security and Robustness of Modern Web Browsers

Despite their popularity, modern web browsers do not offer a secure or robust environment for interacting with untrusted content. Today’s web users face a variety of threats, including exploits of browser vulnerabilities, interference between web sites, script injection attacks, and abuse of authentication credentials. To address these threats, I leverage an analogy between operating systems an...

متن کامل

The Security Architecture of the Chromium Browser

Most current web browsers employ a monolithic architecture that combines “the user” and “the web” into a single protection domain. An attacker who exploits an arbitrary code execution vulnerability in such a browser can steal sensitive files or install malware. In this paper, we present the security architecture of Chromium, the open-source browser upon which Google Chrome is built. Chromium ha...

متن کامل

MashupOS: Operating System Abstractions for Client Mashups

Web browser support has evolved piecemeal to balance the security and interoperability requirements of client-side script services. This evolution has led to an inadequate security model that forces Web applications to choose between security and interoperation. We draw an analogy between Web sites’ sharing of browser resources and users’ sharing of operating system resources, and use this anal...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Computers & Security

دوره 52  شماره 

صفحات  -

تاریخ انتشار 2015