透過您的圖書館登入
IP:216.73.216.60
  • 學位論文

使用者端網頁點擊攔截攻擊之保護

Client-side Clickjacking Attack Prevention

指導教授 : 田筱榮

摘要


近年來web技術發展快速,許多應用操作都移植到網頁上,造成網頁端的攻擊層出不窮。點擊攔截攻擊是近年來出現的一種新的攻擊方式,攻擊者透過各種方式,讓使用者在渾然不知的情況下對網頁執行有惡意目的操作,並藉以竊取私密資料或達到惡意的目的。在這個研究中,我們探討已知的點擊攔截攻擊的特性,並據以提出只需要在使用者端進行不須依靠伺服器端合作的偵測與保護的做法。我們將研究的結果以本論文透過chrome extension的開發環境完成保護機制的實作,我們的測試結果顯示我們提出的做法可以保護使用者避免點擊攔截攻擊意圖網頁的攻擊達到目的。

並列摘要


With the rapid development of web technology, more and more services are delivered to users through the use of it, which also resulted in a ever increasing number of attacks aiming to gain benefit from it. Clickjacking attack is a new attack which tricks users to perform privacy-leaking operations unknowingly. Most of the previously suggested protection schemes depend on server-site participation. Though there are some client-site solutions proposed, there is still a need for a client-site protection scheme which can be easily incoporated to any commonly used web browser and do not inhibit the functionality of any benign web content. In this paper, we investigate the characteristics of the currently known types of clickjacking attacks, and devise client-side employable schemes for the detection and prevention of these attacks . The schemes have been implemented as an extension to one of the commonly used web browser, Chrome. Our experiments show that the proposed schemes can prevent web contents contaminated with clickjacking attacks from achieving their goals.

並列關鍵字

clickjacking likejacking ui_redressing

參考文獻


[3] Xing.L, Zhang.Y and Chen.S, “A Client-Based and Server-Enhanced Defense Mechanism for Cross-Site Request Forgery”,Leture Notes in Computer Science,Volume 6307/2010,Page484-485,2010
[4] Mozilla Content Security Policy,
[6] Balduzzi.M, Egele.M, Kirda.E, Balzarotti.D and Kruege.C,“A Solution For Automated Detection Of Clickjacking Attacks”, ASIACCS 2010, April 13-16,2010,Beijing,China.
[9] Ruderman,J, “The same origin policy”,
[11] Hansen.R,“Clickjacking and GuardedID ha.cker.org web application security lab ,

延伸閱讀