Botnet with Browser Extensions

SocialCom/PASSAT(2011)

引用 10|浏览39
暂无评分
摘要
Botnets are responsible for many large scale organized Internet attacks today. Along with the fight between botnet developers and defenders, the battle field has significantly evolved from traditional centralized IRC to various new approaches, aiming to make bots and command and control channel more and more stealthy. In this work, through prototype implementations, we demonstrate that browser extensions are a very effective botnet vehicle with very large installation base and the capability of accessing rich sensitive user data in the browser. The automatic update mechanism of browser extensions further offers a stealthy command and control channel between bots and a botmaster. Compared to many others, extension-based bots are more stealthy and harder to defeat since all mainstream browser architectures provide rich APIs for browser extensions to enrich users' browsing experience with insufficient consideration of malicious extensions. Via both an IE add-on and a Chrome extension, we show that attacks like email spamming, password sniffing, and DDoS are trivially feasible. Our study shows that an effective scheme is imperatively demanded to mitigate such threats.
更多
查看译文
关键词
command and control channel,password sniffing,online front-ends,botmaster,ie add-ons,email spamming,computer network security,browser extensions,installation base,ie add on,botnet,rich sensitive user data,internet,bot,api,chrome extension,ddos,large scale organized internet attacks,chrome extensions,centralized irc,security of data,command and control,servers,security,internet security,web pages
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要