{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T00:53:49Z","timestamp":1740099229757,"version":"3.37.3"},"publisher-location":"Cham","reference-count":43,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030026400"},{"type":"electronic","value":"9783030026417"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-02641-7_11","type":"book-chapter","created":{"date-parts":[[2018,11,9]],"date-time":"2018-11-09T08:24:09Z","timestamp":1541751849000},"page":"229-249","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Out of the Dark: UI Redressing and Trustworthy Events"],"prefix":"10.1007","author":[{"given":"Marcus","family":"Niemietz","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"J\u00f6rg","family":"Schwenk","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,11,10]]},"reference":[{"key":"11_CR1","unstructured":"Aboukhadijeh, F.: Spy on the webcams of your website visitors, October 2011. http:\/\/feross.org\/webcam-spy\/"},{"key":"11_CR2","unstructured":"Aharonovsky, G.: Malicious camera spying using clickjacking, October 2008. http:\/\/blog.guya.net\/2008\/10\/07\/malicious-camera-spying-using-clickjacking\/"},{"key":"11_CR3","unstructured":"Akhawe, D., He, W., Li, Z., Moazzezi, R., Song, D.: Clickjacking revisited: a perceptual view of UI security. In: 8th USENIX Workshop on Offensive Technologies (WOOT 2014). USENIX Association, San Diego, August 2014. https:\/\/www.usenix.org\/conference\/woot14\/workshop-program\/presentation\/akhawe"},{"key":"11_CR4","doi-asserted-by":"publisher","unstructured":"Balduzzi, M., Egele, M., Kirda, E., Balzarotti, D., Kruegel, C.: A solution for the automated detection of clickjacking attacks. In: Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2010, pp. 135\u2013144. ACM, New York (2010). https:\/\/doi.org\/10.1145\/1755688.1755706","DOI":"10.1145\/1755688.1755706"},{"key":"11_CR5","unstructured":"Barth, A.: The Web Origin Concept. IETF, RFC 6454, December 2011. http:\/\/tools.ietf.org\/html\/rfc6454 , http:\/\/tools.ietf.org\/html\/rfc6454"},{"key":"11_CR6","doi-asserted-by":"crossref","unstructured":"Bianchi, A., Corbetta, J., Invernizzi, L., Fratantonio, Y., Kruegel, C., Vigna, G.: What the app is that? Deception and countermeasures in the android user interface. In: IEEE Symposium on Security and Privacy. Department of Computer Science, University of California, Santa Barbara (2015)","DOI":"10.1109\/SP.2015.62"},{"key":"11_CR7","unstructured":"Bordi, E.: Cursorjacking proof of concept. http:\/\/static.vulnerability.fr\/noscript-cursorjacking.html (August 2010)"},{"key":"11_CR8","unstructured":"Braun, F., Heiderich, M.: X-Frame-Options: All about Clickjacking? (2013) https:\/\/cure53.de\/xfo-clickjacking.pdf"},{"key":"11_CR9","doi-asserted-by":"crossref","unstructured":"Fratantonio, Y., Qian, C., Chung, S., Lee, W.: Cloak and dagger: from two permissions to complete control of the UI feedback loop. In: Proceedings of the IEEE Symposium on Security and Privacy (Oakland), San Jose, CA, May 2017","DOI":"10.1109\/SP.2017.39"},{"key":"11_CR10","unstructured":"Hansen, R., Grossman, J.: Clickjacking attack, December 2008. http:\/\/www.sectheory.com\/clickjacking.htm"},{"key":"11_CR11","unstructured":"Help, G.C.: Allow or block content settings for certain sites, March 2017. https:\/\/support.google.com\/chrome\/answer\/3123708?hl=en"},{"key":"11_CR12","unstructured":"Huang, L.S., Moshchuk, A., Wang, H.J., Schecter, S., Jackson, C.: Clickjacking: attacks and defenses. In: Presented as part of the 21st USENIX Security Symposium (USENIX Security 2012), pp. 413\u2013428. USENIX, Bellevue (2012). https:\/\/www.usenix.org\/conference\/usenixsecurity12\/technical-sessions\/presentation\/huang"},{"key":"11_CR13","unstructured":"Kacmarcik, G., Leithead, T.: UI events - W3C working draft, August 2016. https:\/\/www.w3.org\/TR\/uievents\/"},{"key":"11_CR14","unstructured":"Kaminsky, D., Huang, D.L.S., Maone, G.: W3C - user interface security and the visibility API, June 2016. https:\/\/www.w3.org\/TR\/UISecurity\/"},{"key":"11_CR15","unstructured":"Kotowicz, K.: Cursorjacking again, January 2012. http:\/\/blog.kotowicz.net\/2012\/01\/cursorjacking-again.html"},{"key":"11_CR16","unstructured":"Lawrence, E.: Combating clickjacking with x-frame-options, March 2010. http:\/\/blogs.msdn.com\/b\/ieinternals\/archive\/2010\/03\/30\/combating-clickjacking-with-x-frame-options.aspx"},{"key":"11_CR17","unstructured":"Lekies, S., Heiderich, M., Appelt, D., Holz, T.: On the fragility and limitations of current browser-provided clickjacking protection schemes. In: Presented as Part of the 6th USENIX Workshop on Offensive Technologies. USENIX, Berkeley (2012). https:\/\/www.usenix.org\/conference\/woot12\/workshop-program\/presentation\/Lekies"},{"key":"11_CR18","unstructured":"Lekies, S., Heiderich, M., Appelt, D., Holz, T., Johns, M.: On the fragility and limitations of current browser-provided clickjacking protection schemes. In: USENIX Workshop on Offensive Technologies (WOOT 2012) (2012)"},{"key":"11_CR19","doi-asserted-by":"crossref","unstructured":"Lin, C.C., Li, H., Zhou, X., Wang, X.: Screenmilker: how to milk your android screen for secrets. In: Network and Distributed System Security (NDSS) Symposium 2014 (2014)","DOI":"10.14722\/ndss.2014.23049"},{"key":"11_CR20","unstructured":"Maone, G., Huang, D.L.S., Gondrom, T., Hill, B.: W3C - user interface security directives for content security policy, June 2014. https:\/\/dvcs.w3.org\/hg\/user-interface-safety\/raw-file\/tip\/user-interface-safety.html"},{"key":"11_CR21","doi-asserted-by":"crossref","unstructured":"Mayer, A., Niemietz, M., Mladenov, V., Schwenk, J.: Guardians of the clouds: when identity providers fail. In: The ACM Cloud Computing Security Workshop, CCSW 2014 (2014)","DOI":"10.1145\/2664168.2664171"},{"key":"11_CR22","unstructured":"Microsoft: How to use security zones in internet explorer, June 2012. https:\/\/support.microsoft.com\/en-us\/help\/174360\/how-to-use-security-zones-in-internet-explorer"},{"key":"11_CR23","unstructured":"Needham, K.: The future of developing firefox add-ons, August 2015. https:\/\/blog.mozilla.org\/addons\/2015\/08\/21\/the-future-of-developing-firefox-add-ons\/"},{"key":"11_CR24","unstructured":"Network, M.D.: Event.istrusted, February 2017. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Event\/isTrusted"},{"key":"11_CR25","unstructured":"Network, M.D.: Web apis - document.execcommand(), January 2017. https:\/\/developer.mozilla.org\/de\/docs\/Web\/API\/Document\/execCommand"},{"key":"11_CR26","unstructured":"Niemietz, M.: Clickjacking und UI-Redressing - Vom Klick-Betrug zum Datenklau: Ein Leitfaden f\u00fcr Sicherheitsexperten und Webentwickler. dpunkt-Verlag (2012)"},{"key":"11_CR27","unstructured":"Niemietz, M.: UI Redressing: Attacks and Countermeasures Revisited. In: CONFidence, May 2011"},{"key":"11_CR28","unstructured":"Niemietz, M., Schwenk, J.: UI Redressing Attacks on Android Devices, December 2012. https:\/\/media.blackhat.com\/ad-12\/Niemietz\/bh-ad-12-androidmarcus_niemietz-WP.pdf"},{"key":"11_CR29","unstructured":"Niemietz, M., Schwenk, J.: Owning your home network: router security revisited. In: Web 2.0 Security & Privacy 2015, San Jose (2015). http:\/\/ieee-security.org\/TC\/SPW2015\/W2SP\/papers\/W2SP_2015_submission_9.pdf"},{"key":"11_CR30","doi-asserted-by":"crossref","unstructured":"Roesner, F., Kohno, T., Moshchuk, A., Parno, B., Wang, H., Cowan, C.: User-driven access control: Rethinking permission granting in modern operating systems. In: 2012 IEEE Symposium on Security and Privacy (SP), pp. 224\u2013238, May 2012","DOI":"10.1109\/SP.2012.24"},{"key":"11_CR31","unstructured":"Ruderman, J.: The same origin policy (2008). http:\/\/www-archive.mozilla.org\/projects\/security\/components\/same-origin.html"},{"key":"11_CR32","unstructured":"Rydstedt, G., Bursztein, E., Boneh, D.: Framing attacks on smart phones and dumb routers: tap-jacking and geo-localization. In: in USENIX Workshop on Offensive Technologies (wOOt 2010) (2010). http:\/\/seclab.stanford.edu\/websec\/framebusting\/tapjacking.pdf"},{"key":"11_CR33","unstructured":"Rydstedt, G., Bursztein, E., Boneh, D., Jackson, C.: Busting frame busting: a study of clickjacking vulnerabilities at popular sites. In: IEEE Oakland Web 2.0 Security and Privacy (W2SP 2010) (2010). http:\/\/seclab.stanford.edu\/websec\/framebusting\/framebust.pdf"},{"key":"11_CR34","unstructured":"Sherman, I.: Making form-filling faster, easier and smarter, January 2012. https:\/\/webmasters.googleblog.com\/2012\/01\/making-form-filling-faster-easier-and.html"},{"key":"11_CR35","unstructured":"Sophos: Facebook worm - \u201clikejacking\u201d, May 2010. http:\/\/nakedsecurity.sophos.com\/2010\/05\/31\/facebook-likejacking-worm\/"},{"key":"11_CR36","doi-asserted-by":"publisher","unstructured":"Stamm, S., Sterne, B., Markham, G.: Reining in the web with content security policy. In: Proceedings of the 19th International Conference on World Wide Web, WWW 2010, pp. 921\u2013930. ACM, New York (2010). https:\/\/doi.org\/10.1145\/1772690.1772784","DOI":"10.1145\/1772690.1772784"},{"key":"11_CR37","unstructured":"Steen, H.R.M.: W3C - clipboard API and events, December 2016. https:\/\/www.w3.org\/TR\/clipboard-apis\/"},{"key":"11_CR38","unstructured":"Stone, P.: Next generation clickjacking - new attacks against framed web pages, April 2010. https:\/\/www.contextis.com\/documents\/5\/Context-Clickjacking_white_paper.pdf"},{"key":"11_CR39","unstructured":"W3C: W3C DOM4: Dom event istrusted, November 2015. https:\/\/www.w3.org\/TR\/dom\/"},{"key":"11_CR40","unstructured":"W3C: UI events, January 2016. https:\/\/w3c.github.io\/uievents\/"},{"key":"11_CR41","unstructured":"WHATWG: Html, living standard - drag and drop, November 2013. http:\/\/www.whatwg.org\/specs\/web-apps\/current-work\/multipage\/dnd.html#dnd"},{"key":"11_CR42","unstructured":"WHATWG: form control infrastructure, July 2017. https:\/\/html.spec.whatwg.org\/multipage\/form-control-infrastructure.html"},{"key":"11_CR43","unstructured":"Zalewski, M.: Strokejacking, June 2010. http:\/\/lcamtuf.blogspot.de\/2010\/06\/curse-of-inverse-strokejacking.html"}],"container-title":["Lecture Notes in Computer Science","Cryptology and Network Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-02641-7_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,11,1]],"date-time":"2019-11-01T03:19:17Z","timestamp":1572578357000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-02641-7_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030026400","9783030026417"],"references-count":43,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-02641-7_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"CANS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Cryptology and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hong Kong","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 November 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 December 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cans2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/crypto.ie.cuhk.edu.hk\/cans17\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"88","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"20","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"8","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"23% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"6","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}}]}}