[Back]


Contributions to Proceedings:

A. Sjösten, S. Van Acker, A. Sabelfeld:
"Discovering Browser Extensions via Web Accessible Resources";
in: "7th ACM Conference on Data and Application Security and Privacy", ACM, 2017, ISBN: 978-1-4503-4523-1, 329 - 336.



English abstract:
Browser extensions provide a powerful platform to enrich browsing experience. At the same time, they raise important security questions. From the point of view of a website, some browser extensions are invasive, removing intended features and adding unintended ones, e.g. extensions that hijack Facebook likes. Conversely, from the point of view of extensions, some websites are invasive, e.g. websites that bypass ad blockers. Motivated by security goals at clash, this paper explores browser extension discovery, through a non-behavioral technique, based on detecting extensions' web accessible resources. We report on an empirical study with free Chrome and Firefox extensions, being able to detect over 50% of the top 1,000 free Chrome extensions, including popular security- and privacy-critical extensions such as AdBlock, LastPass, Avast Online Security, and Ghostery. We also conduct an empirical study of non-behavioral extension detection on the Alexa top 100,000 websites. We present the dual measures of making extension detection easier in the interest of websites and making extension detection more difficult in the interest of extensions. Finally, we discuss a browser architecture that allows a user to take control in arbitrating the conflicting security goals.


"Official" electronic version of the publication (accessed through its Digital Object Identifier - DOI)
http://dx.doi.org/10.1145/3029806.3029820

Electronic version of the publication:
https://publik.tuwien.ac.at/files/publik_296696.pdf


Created from the Publication Database of the Vienna University of Technology.