Hardening the security analysis of browser extensions


연구 분야: Analysis



학회: SAC '22: Proceedings of the 37th ACM/SIGAPP Symposium on Applied Computing


초록

Browser extensions boost the browsing experience by a range of features from automatic translation and grammar correction to password management, ad blocking, and remote desktops. Yet the power of extensions poses significant privacy and security challenges because extensions can be malicious and/or vulnerable. We observe that there are gaps in the previous work on analyzing the security of browser extensions and present a systematic study of attack entry points in the browser extension ecosystem. Our study reveals novel password stealing, traffic stealing, and inter-extension attacks. Based on a combination of static and dynamic analysis we show how to discover extension attacks, both known and novel ones, and study their prevalence in the wild. We show that 1,349 extensions are vulnerable to inter-extension attacks leading to XSS. Our empirical study uncovers a remarkable cluster of "New Tab" extensions where 4,410 extensions perform traffic stealing attacks. We suggest several avenues for the countermeasures against the uncovered attacks, ranging from refining the permission model to mitigating the attacks by declarations in manifest files.


Author Profile
Benjamin Eriksson

Chalmers University of Technology

정보 없음
Author Profile
Pablo Picazo-Sanchez

Chalmers University of Technology

정보 없음
Author Profile
Andrei Sabelfeld

Chalmers University of Technology

정보 없음

📄 논문 정보

발행 연도 2022년
인용수 15
출판 국가
사이트 ACM
좋아요 수 0

연관 논문 목록 (106건)