{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T18:59:26Z","timestamp":1726081166481},"publisher-location":"Singapore","reference-count":24,"publisher":"Springer Singapore","isbn-type":[{"type":"print","value":"9789811548246"},{"type":"electronic","value":"9789811548253"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-981-15-4825-3_5","type":"book-chapter","created":{"date-parts":[[2020,4,25]],"date-time":"2020-04-25T08:02:53Z","timestamp":1587801773000},"page":"60-71","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Man-in-the-browser Attack: A Case Study on Malicious Browser Extensions"],"prefix":"10.1007","author":[{"given":"Sampsa","family":"Rauti","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,4,26]]},"reference":[{"key":"5_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-34210-3_1","volume-title":"Secure IT Systems","author":"A Blom","year":"2012","unstructured":"Blom, A., de Koning Gans, G., Poll, E., de Ruiter, J., Verdult, R.: Designed to fail: a USB-connected reader for online banking. In: J\u00f8sang, A., Carlsson, B. (eds.) NordSec 2012. LNCS, vol. 7617, pp. 1\u201316. Springer, Heidelberg (2012). \nhttps:\/\/doi.org\/10.1007\/978-3-642-34210-3_1"},{"key":"5_CR2","unstructured":"DeKoven, L.F., Savage, S., Voelker, G.M., Leontiadis, N.: Malicious browser extensions at scale: bridging the observability gap between web site and browser. In: 10th USENIX Workshop on Cyber Security Experimentation and Test (CSET 2017). USENIX Association, Vancouver, BC (2017), \nhttps:\/\/www.usenix.org\/conference\/cset17\/workshop-program\/presentation\/dekoven"},{"key":"5_CR3","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1007\/978-3-662-45472-5_24","volume-title":"Financial Cryptography and Data Security","author":"A Dmitrienko","year":"2014","unstructured":"Dmitrienko, A., Liebchen, C., Rossow, C., Sadeghi, A.R.: On the (in)security of mobile two-factor authentication. In: Christin, N., Safavi-Naini, R. (eds.) Financial Cryptography and Data Security, pp. 365\u2013383. Springer, Berlin Heidelberg (2014). \nhttps:\/\/doi.org\/10.1007\/978-3-662-45472-5_24"},{"issue":"1","key":"5_CR4","doi-asserted-by":"publisher","first-page":"29","DOI":"10.4018\/jaci.2012010103","volume":"4","author":"T Dougan","year":"2012","unstructured":"Dougan, T., Curran, K.: Man in the browser attacks. Int. J. Ambient Comput. Intell. (IJACI) 4(1), 29\u201339 (2012)","journal-title":"Int. J. Ambient Comput. Intell. (IJACI)"},{"key":"5_CR5","unstructured":"Entrust: Defeating Man-in-the-Browser Malware - How to prevent the latest malware attacks against consumer and corporate banking. White paper (2014)"},{"key":"5_CR6","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1016\/j.cose.2019.03.013","volume":"84","author":"A Gezer","year":"2019","unstructured":"Gezer, A., Warner, G., Wilson, C., Shrestha, P.: A flow-based approach for trickbot banking trojan detection. Comput. Secur. 84, 179\u2013192 (2019)","journal-title":"Comput. Secur."},{"key":"5_CR7","unstructured":"Google: Content scripts (2019). \nhttps:\/\/developer.chrome.com\/extensions\/content_scripts"},{"key":"5_CR8","doi-asserted-by":"crossref","unstructured":"Guha, A., Fredrikson, M., Livshits, B., Swamy, N.: Verified security for browser extensions. In: 2011 IEEE Symposium on Security and Privacy, pp. 115\u2013130. IEEE (2011)","DOI":"10.1109\/SP.2011.36"},{"key":"5_CR9","unstructured":"G\u00fchring, P.: Concepts against man-in-the-browser attacks. Technical report (2006)"},{"key":"5_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"405","DOI":"10.1007\/978-3-662-54970-4_24","volume-title":"Financial Cryptography and Data Security","author":"RK Konoth","year":"2017","unstructured":"Konoth, R.K., van der Veen, V., Bos, H.: How anywhere computing just killed your phone-based two-factor authentication. In: Grossklags, J., Preneel, B. (eds.) FC 2016. LNCS, vol. 9603, pp. 405\u2013421. Springer, Heidelberg (2017). \nhttps:\/\/doi.org\/10.1007\/978-3-662-54970-4_24"},{"key":"5_CR11","unstructured":"Liu, L., Zhang, X., Yan, G., Chen, S., et al.: Chrome extensions: threat analysis and countermeasures. In: NDSS (2012)"},{"key":"5_CR12","unstructured":"Marinho, R.: \u201cCatch-All\u201d Google Chrome Malicious Extension Steals All Posted Data (2017). \nhttps:\/\/morphuslabs.com\/catch-all-google-chrome-malicious-extension-steals-all-posted-data-f2472e272101"},{"key":"5_CR13","doi-asserted-by":"crossref","unstructured":"Marouf, S., Shehab, M.: Towards improving browser extension permission management and user awareness. In: 8th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), pp. 695\u2013702. IEEE (2012)","DOI":"10.4108\/icst.collaboratecom.2012.250642"},{"key":"5_CR14","doi-asserted-by":"crossref","unstructured":"Migdal, D., Johansen, C., J\u00f8sang, A.: DEMO: OffPAD - offline personal authenticating device with applications in hospitals and e-banking. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security CCS 2016, pp. 1847\u20131849. ACM, New York, NY, USA (2016)","DOI":"10.1145\/2976749.2989033"},{"key":"5_CR15","unstructured":"OWASP: Man-in-the-browser attack (2019). \nhttps:\/\/www.owasp.org\/index.php\/Man-in-the-browser_attack"},{"key":"5_CR16","unstructured":"Protalinski, E.: Google updates Chrome Web Store review process and sets new extension code requirements (2018). \nhttps:\/\/venturebeat.com\/2018\/06\/12\/google-disables-inline-installation-for-chrome-extensions\/"},{"key":"5_CR17","doi-asserted-by":"crossref","unstructured":"Rauti, S., Lepp\u00e4nen, V.: Man-in-the-browser attacks in modern web browsers. In: Emerging Trends in ICT Security, pp. 469\u2013480. Elsevier (2014)","DOI":"10.1016\/B978-0-12-411474-6.00028-1"},{"issue":"4","key":"5_CR18","doi-asserted-by":"publisher","first-page":"253","DOI":"10.1504\/IJITST.2012.054058","volume":"4","author":"M Rautila","year":"2012","unstructured":"Rautila, M., Suomalainen, J.: Secure inspection of web transactions. Int. J. Internet Technol. Secur. Trans. 4(4), 253\u2013271 (2012)","journal-title":"Int. J. Internet Technol. Secur. Trans."},{"key":"5_CR19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-8348-9283-6_39","volume-title":"ISSE 2008 Securing Electronic Business Processes","author":"C Ronchi","year":"2009","unstructured":"Ronchi, C., Zakhidov, S.: Hardened client platforms for secure internet banking. In: Pohlmann, N., Reimer, H., Schneider, W. (eds.) ISSE 2008 Securing Electronic Business Processes. Springer, Heidelberg (2009). \nhttps:\/\/doi.org\/10.1007\/978-3-8348-9283-6_39"},{"key":"5_CR20","unstructured":"St\u00e5hlberg, M.: The trojan money spinner. In: Virus Bulletin Conference, vol. 4 (2007)"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Toreini, E., Shahandashti, S.F., Mehrnezhad, M., Hao, F.: Domtegrity: ensuring web page integrity against malicious browser extensions. Int. J. Inf. Secur. 1\u201314 (2019)","DOI":"10.1007\/s10207-019-00442-1"},{"key":"5_CR22","unstructured":"Utakrit, N.: Review of browser extensions, a man-in-the-browser phishing techniques targeting bank customers (2009)"},{"key":"5_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/978-3-642-29101-2_11","volume-title":"Information Security Practice and Experience","author":"L Wang","year":"2012","unstructured":"Wang, L., Xiang, J., Jing, J., Zhang, L.: Towards fine-grained access control on browser extensions. In: Ryan, M.D., Smyth, B., Wang, G. (eds.) ISPEC 2012. LNCS, vol. 7232, pp. 158\u2013169. Springer, Heidelberg (2012). \nhttps:\/\/doi.org\/10.1007\/978-3-642-29101-2_11"},{"issue":"2","key":"5_CR24","doi-asserted-by":"publisher","first-page":"137","DOI":"10.4018\/IJDCF.2018040108","volume":"10","author":"P Zhang","year":"2018","unstructured":"Zhang, P., He, Y., Chow, K.: Fraud track on secure electronic check system. Int. J. Digit. Crime Forensics 10(2), 137\u2013144 (2018)","journal-title":"Int. J. Digit. Crime Forensics"}],"container-title":["Communications in Computer and Information Science","Security in Computing and Communications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-15-4825-3_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,25]],"date-time":"2020-04-25T08:04:08Z","timestamp":1587801848000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-981-15-4825-3_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9789811548246","9789811548253"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-981-15-4825-3_5","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"26 April 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SSCC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Security in Computing and Communication","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Trivandrum","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 December 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 December 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sscc2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.acn-conference.org\/sscc2019\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EDAS","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"61","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"22","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"36% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}