返回
SENTINEL: Securing Legacy Firefox Extensions
DOI:10.1016/j.cose.2014.12.002.png)
摘要
En 中文
A poorly designed web browser extension with a security vulnerability may expose the whole system to an attacker. Therefore, attacks directed at benign-but-buggy extensions, as well as extensions that have been written with malicious intent, pose significant security threats to a system running such components. Recent studies have indeed shown that many Firefox extensions are over-privileged, making them attractive attack targets. Unfortunately, users currently do not have many options when it comes to protecting themselves from extensions that may potentially be malicious. Once installed and executed, the extension is considered trusted. This paper introduces SENTINEL, a policy enforcer for the Firefox browser that gives fine-grained control to the user over the actions of existing JavaScript Firefox extensions. The user is able to define policies (or use predefined ones) and block common attacks such as data exfiltration, remote code execution, saved password theft, preference modification, phishing, browser window clickjacking, and namespace collision exploits. Our evaluation of SENTINEL shows that our prototype implementation can effectively prevent concrete, real-world Firefox extension attacks without a detrimental impact on the user's browsing experience. (C) 2014 Elsevier Ltd. All rights reserved.
Keyword:
Web browser security
Extension security
Browser extensions
Malicious extensions
JavaScript extensions
Firefox
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W

