Securing User Input as a Defense Against MitB

作者: Radhesh Krishnan K , Renuka Kumar , None

DOI: 10.1145/2660859.2660964

关键词: TrojanEnd userSoftware systemTransport Layer SecurityDatabase transactionAuthenticationNoticeMulti-factor authenticationComputer securityInternet privacyEngineering

摘要: In MitB is a sophisticated form of attack wherein Trojan or bot embedded in the browser steals and tampers with legitimate user data. Online banking websites have all along been favourite playground for these bots. While most sites employ multi-factor authentication, one-time pads transactions, even presence Secure Sockets Layer channel they are still not resilient against attacks. This paper demonstrates how vulnerable our web accounts to using two significant real life examples - Gmail account secured Google's 2-step verification an online transaction. The also talks about defending by identifying securing inputs system that will be weakest link device transaction authorization chain. nature this such happen so silently, may notice any malicious activity simply disregard unnatural behaviour as oversight on part himself technical difficulty. Hence, what reiterates that, engineers software systems, security has enforced end when required must left option tech savvy users alone.

参考文章(6)
Elie Bursztein, Dan Boneh, Collin Jackson, Gaurav Aggarwal, An analysis of private browsing modes in modern browsers usenix security symposium. pp. 6- 6 ,(2010)
M A Sasse, S Brostoff, D Weirich, Transforming the 'Weakest Link' — a Human/Computer Interaction Approach to Usable and Effective Security Bt Technology Journal. ,vol. 19, pp. 122- 131 ,(2001) , 10.1023/A:1011902718709
Timothy Dougan, Kevin Curran, Man in the Browser Attacks International Journal of Ambient Computing and Intelligence. ,vol. 4, pp. 29- 39 ,(2012) , 10.4018/JACI.2012010103
P. Goyal, N. Bansal, N. Gupta, Averting man in the browser attack using user-specific personal images ieee international advance computing conference. pp. 1283- 1286 ,(2013) , 10.1109/IADCC.2013.6514413
Luis von Ahn, Manuel Blum, John Langford, Telling humans and computers apart automatically Communications of the ACM. ,vol. 47, pp. 56- 60 ,(2004) , 10.1145/966389.966390