Skip to main content

2017 | OriginalPaper | Buchkapitel

STRIDE Based Analysis of the Chrome Browser Extensions API

verfasst von : P. K. Akshay Dev, K. P. Jevitha

Erschienen in: Proceedings of the 5th International Conference on Frontiers in Intelligent Computing: Theory and Applications

Verlag: Springer Singapore

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Chrome browser extensions have become very popular among the users of Google Chrome and hence they are used by attackers to perform malicious activities which lead to loss of user’s sensitive data or damage to the user’s system. In this study, we have done an analysis on the security of the Chrome extension development APIs. We have used the STRIDE approach to identify the possible threats of the Chrome specific APIs which are used for extension development. The analysis results show that 23 out of the 63 Chrome specific APIs are having various threats as per the STRIDE approach. Information disclosure is the threat faced by many APIs followed by tampering. This threat analysis result can be used as reference for a tool which can detect whether the extension is malicious or not by deeply analysing the ways in which the APIs having threats are used in the extension code.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat L. Liu, X. Zhang, G. Yan, S. Chen, Chrome extensions: threat analysis and countermeasures, in NDSS (2012) L. Liu, X. Zhang, G. Yan, S. Chen, Chrome extensions: threat analysis and countermeasures, in NDSS (2012)
3.
Zurück zum Zitat S.F. Burns, Threat modeling: a process to ensure application security, in GIAC Security Essentials Certification (GSEC) Practical Assignment (2005) S.F. Burns, Threat modeling: a process to ensure application security, in GIAC Security Essentials Certification (GSEC) Practical Assignment (2005)
4.
Zurück zum Zitat N. Carlini, A. Porter Felt, D. Wagner, An evaluation of the google chrome extension security architecture, in Presented as Part of the 21st USENIX Security Symposium (USENIX Security 12), pp. 97–111 (2012) N. Carlini, A. Porter Felt, D. Wagner, An evaluation of the google chrome extension security architecture, in Presented as Part of the 21st USENIX Security Symposium (USENIX Security 12), pp. 97–111 (2012)
5.
Zurück zum Zitat V. Aravind, M. Sethumadhavan, A framework for analysing the security of chrome extensions. Adv. Comput. Netw. Inf. 2, 267–272 (2014) V. Aravind, M. Sethumadhavan, A framework for analysing the security of chrome extensions. Adv. Comput. Netw. Inf. 2, 267–272 (2014)
6.
Zurück zum Zitat J. Arunagiri, S. Rakhi, K.P. Jevitha, A systematic review of security measures for web browser extension vulnerabilities, in Proceedings of the International Conference on Soft Computing Systems (Springer India, 2016) J. Arunagiri, S. Rakhi, K.P. Jevitha, A systematic review of security measures for web browser extension vulnerabilities, in Proceedings of the International Conference on Soft Computing Systems (Springer India, 2016)
7.
Zurück zum Zitat R. Zhao, C. Yue, Q. Yi, Automatic detection of information leakage vulnerabilities in browser extensions, in Proceedings of the 24th International Conference on World Wide Web (International World Wide Web Conferences Steering Committee, 2015) R. Zhao, C. Yue, Q. Yi, Automatic detection of information leakage vulnerabilities in browser extensions, in Proceedings of the 24th International Conference on World Wide Web (International World Wide Web Conferences Steering Committee, 2015)
8.
Zurück zum Zitat A. Kapravelos, et al., Hulk: eliciting malicious behavior in browser extensions, in 23rd USENIX Security Symposium (USENIX Security 14) (2014) A. Kapravelos, et al., Hulk: eliciting malicious behavior in browser extensions, in 23rd USENIX Security Symposium (USENIX Security 14) (2014)
9.
Zurück zum Zitat N. Jagpal, et al., Trends and lessons from three years fighting malicious extensions, in 24th USENIX Security Symposium (USENIX Security 15) (2015) N. Jagpal, et al., Trends and lessons from three years fighting malicious extensions, in 24th USENIX Security Symposium (USENIX Security 15) (2015)
10.
Zurück zum Zitat K. Onarlioglu, et al., Sentinel: securing legacy firefox extensions. Comput. Secur. 49, 147–161 (2015) K. Onarlioglu, et al., Sentinel: securing legacy firefox extensions. Comput. Secur. 49, 147–161 (2015)
11.
Zurück zum Zitat X. Xing, et al., Understanding malvertising through ad-injecting browser extensions, in Proceedings of the 24th International Conference on World Wide Web (International World Wide Web Conferences Steering Committee, 2015) X. Xing, et al., Understanding malvertising through ad-injecting browser extensions, in Proceedings of the 24th International Conference on World Wide Web (International World Wide Web Conferences Steering Committee, 2015)
Metadaten
Titel
STRIDE Based Analysis of the Chrome Browser Extensions API
verfasst von
P. K. Akshay Dev
K. P. Jevitha
Copyright-Jahr
2017
Verlag
Springer Singapore
DOI
https://doi.org/10.1007/978-981-10-3156-4_17

Premium Partner