A Browser-Based Distributed System For The Detection Of Https Stripping Attacks Against Web Pages

INFORMATION SECURITY AND PRIVACY RESEARCH(2012)

引用 1|浏览9
暂无评分
摘要
HTTPS stripping attacks leverage a combination of weak configuration choices to trick users into providing sensitive data through hijacked connections. Here we present a browser extension that helps web users to detect this kind of integrity and authenticity breaches, by extracting relevant features from the browsed pages and comparing them to reference values coming from different sorts of trusted sources. The rationale behind the extension is discussed and its effectiveness is demonstrated with some quantitative results, gathered on the prototype that has been implemented for Mozilla Firefox.
更多
查看译文
关键词
HTTPS stripping, Peer-to-peer, Browser plugin
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要