Loading...

Proceedings of

International Conference on Advances in Computer Science and Electronics Engineering CSEE 2013

"REVIEW OF MAN-IN-THE-BROWSER ATTACK USING SECURITY ATTACK SCENARIOS"

ANIL SAINI MANOJ SINGH GAUR VIJAYALAKSHMI
DOI
10.15224/978-981-07-5461-7-11
Pages
50 - 54
Authors
3
ISBN
978-981-07-5461-7

Abstract: “A Web browser is an important component of every computer system as it provides the interface to the Internet world. Browsers facilitate the web users through online services like e-mail, banking and shopping. The new unforeseen functionalities may be added to the web browsers in the form of extensions. The extensions have access to sensitive browser APIs and untrusted web page content, which may result in browser attack like Man-in-the-Browser attack. The major target of this attack is customers of Internet banking. This paper makes two major contributions. First, it presents the threat model for Man-in-the-Browser (MITB) attack. This model identifies various threats and point of attacks used by MITB attack. The major cause of MITB attack is malicious extensions and vulnerabilities found in benign-but-buggy browser extensions. In our study we find that the current browser security model is not secure enough to protect against MITB attack. Second, this paper presents the possible secur”

Keywords: Threat model, Browser extensions, Vulnerabilities, Browser attack, Security attack scenarios

Download PDF