{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T08:03:04Z","timestamp":1784361784143,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":39,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819230174","type":"print"},{"value":"9789819230181","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-92-3018-1_20","type":"book-chapter","created":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T07:26:45Z","timestamp":1784359605000},"page":"435-465","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Data Exfiltration over\u00a0Browser"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-6201-8878","authenticated-orcid":false,"given":"Naseer Ahmad","family":"Noor","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2761-6097","authenticated-orcid":false,"given":"Masahiro","family":"Ishii","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1330-4495","authenticated-orcid":false,"given":"Keisuke","family":"Tanaka","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,18]]},"reference":[{"key":"20_CR1","unstructured":"Akhawe, D., Felt, A.P.: Alice in warningland: a large-scale field study of browser security warning effectiveness. In: 22nd USENIX Security Symposium (USENIX Security 13), pp. 257\u2013272. USENIX Association, Washington, D.C. (2013). https:\/\/www.usenix.org\/conference\/usenixsecurity13\/technical-sessions\/presentation\/akhawe"},{"key":"20_CR2","unstructured":"Avast: avast - antivirus and security software (2025). https:\/\/www.avast.co.jp\/store#mac. Accessed 29 Mar 2025"},{"key":"20_CR3","unstructured":"Avast: Avast online security & privacy. Chrome Web Store (2025). https:\/\/chromewebstore.google.com\/detail\/avast-online-security-pri\/gomekmidlodglbbmalcneegieacbdmki?hl=en. Accessed 13 Feb 2026"},{"key":"20_CR4","unstructured":"BlackFog: the state of ransomware 2024. https:\/\/privacy.blackfog.com\/wp-content\/uploads\/2025\/02\/2024-State-of-Ransomware-Annual-Report_v1.pdf (2025). Accessed 26 Apr 2026"},{"key":"20_CR5","unstructured":"Brave: Remove Support for Native File System API (2019). https:\/\/github.com\/brave\/brave-browser\/issues\/11407#issuecomment-851742821. Accessed 26 Mar 2025"},{"key":"20_CR6","unstructured":"Can I Use: Can I use File System Access API? (2023). https:\/\/caniuse.com\/native-filesystem-api. Accessed 26 Mar 2025"},{"key":"20_CR7","doi-asserted-by":"crossref","unstructured":"Chandel, S., Sun, Y., Tang, Y., Zhou, Z., Huang, Y.: Endpoint protection: measuring the effectiveness of remediation technologies and methodologies for insider threat. In: 2019 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC) pp. 81\u201389 (2019). https:\/\/api.semanticscholar.org\/CorpusID:209853822","DOI":"10.1109\/CyberC.2019.00023"},{"key":"20_CR8","unstructured":"Chrome Developers: Chrome 134 release notes (2025). https:\/\/developer.chrome.com\/release-notes\/134. Accessed 26 Apr 2026"},{"key":"20_CR9","unstructured":"Chrome Developers: Chrome 136 release notes (2025). https:\/\/developer.chrome.com\/release-notes\/136. Accessed 26 Apr 2026"},{"key":"20_CR10","unstructured":"Chrome Developers: File system access API (2025). https:\/\/developer.chrome.com\/docs\/capabilities\/web-apis\/file-system-access. Accessed 26 Apr 2026"},{"key":"20_CR11","unstructured":"Chrome Developers: Chrome 147 release notes (2026). https:\/\/developer.chrome.com\/release-notes\/147. Accessed 26 Apr 2026"},{"key":"20_CR12","unstructured":"Chromium: Update file system permission dialogs for read & readwrite accesses (2025). https:\/\/chromium.googlesource.com\/chromium\/src\/+\/5b8b36772fbb0a49fa285efe5fb585f4093c2cb3"},{"key":"20_CR13","unstructured":"Cloudmersive: Cloudmersive API portal (2025). https:\/\/portal.cloudmersive.com\/default. Accessed 28 Mar 2025"},{"key":"20_CR14","unstructured":"Docs, M.W.: Same-origin policy (2025). https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/Security\/Same-origin_policy. Accessed 29 Mar 2025"},{"key":"20_CR15","unstructured":"Faculty, I.: Data exfiltration: insider threat detection & prevention tactics (2021). https:\/\/www.iansresearch.com\/resources\/all-blogs\/post\/security-blog\/2021\/08\/03\/data-exfiltration-insider-threat-detection-prevention-tactics. Accessed 02 Apr 2025"},{"key":"20_CR16","unstructured":"Fortinet: What is data exfiltration? (2024). https:\/\/www.fortinet.com\/resources\/cyberglossary\/data-exfiltration. Accessed 26 Mar 2025"},{"key":"20_CR17","doi-asserted-by":"publisher","unstructured":"Han, X., Xiong, J., Shen, W., Lu, Z., Liu, Y.: The rise of WI-FI spoofing attack via geolocation API. In: Proceedings of the 2022 ACM SIGSAC, pp. 1383\u20131397. CCS \u201922. ACM, New York, NY, USA (2022). https:\/\/doi.org\/10.1145\/3548606.3560623","DOI":"10.1145\/3548606.3560623"},{"key":"20_CR18","unstructured":"IBM Security: Cost of a data breach report 2024 (2024). https:\/\/www.ibm.com\/reports\/data-breach. Accessed 26 Apr 2026"},{"key":"20_CR19","unstructured":"Kaspersky: kaspersky home security solutions (2025). https:\/\/www.kaspersky.com\/home-security. Accessed 29 Mar 2025"},{"key":"20_CR20","unstructured":"Kaspersky Lab: Kaspersky protection browser extension. Kaspersky Support (2022). https:\/\/support.kaspersky.com\/kfa\/97156. Accessed 13 Feb 2026, iD: 97156."},{"key":"20_CR21","unstructured":"King, J., Bendiab, G., Savage, N., Shiaeles, S.: Data exfiltration: methods and detection countermeasures. Cyber Secur. Res. Group Univ. Portsmouth (2025). https:\/\/pure.port.ac.uk\/ws\/portalfiles\/portal\/42722347\/Data_Exfiltration.pdf"},{"key":"20_CR22","unstructured":"Malwarebytes: Malwarebytes - cybersecurity for home and business (2025). https:\/\/www.malwarebytes.com\/. Accessed 29 Mar 2025"},{"key":"20_CR23","unstructured":"Malwarebytes: Malwarebytes browser guard - chrome web store (2025). https:\/\/chromewebstore.google.com\/detail\/malwarebytes-browser-guar\/ihcjicgdanjaechkgeegckofjjedodee. Accessed 29 Mar 2025"},{"key":"20_CR24","unstructured":"MDN Web Docs: Fetch API (2025). https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Fetch_API. Accessed 27 Mar 2025"},{"issue":"1","key":"20_CR25","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1177\/1071181319631044","volume":"63","author":"KA Molinaro","year":"2019","unstructured":"Molinaro, K.A., Bolton, M.L.: Using the lens model and cognitive continuum theory to understand the effects of cognition on phishing victimization. Proc. Hum. Fact. Ergon. Soc. Ann. Meeting 63(1), 173\u2013177 (2019). https:\/\/doi.org\/10.1177\/1071181319631044","journal-title":"Proc. Hum. Fact. Ergon. Soc. Ann. Meeting"},{"key":"20_CR26","unstructured":"Mozilla: Mozilla Specification Positions (2022). https:\/\/mozilla.github.io\/standards-positions\/#file-system-access. Accessed 26 Mar 2025"},{"key":"20_CR27","doi-asserted-by":"publisher","unstructured":"Oz, H., Acar, A., Aris, A., Tuncay, G.S., Kharraz, A., Uluagac, S.: (in)security of file uploads in node.js. In: Proceedings of the ACM Web Conference 2024, pp. 1573\u20131584. WWW \u201924, Association for Computing Machinery, New York, NY, USA (2024). https:\/\/doi.org\/10.1145\/3589334.3645342","DOI":"10.1145\/3589334.3645342"},{"key":"20_CR28","unstructured":"Oz, H., Aris, A., Acar, A., Tuncay, G.S., Babun, L., Uluagac, S.: R\u00f8B: Ransomware over modern web browsers. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 7073\u20137090. USENIX Association, Anaheim, CA (2023). https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/oz"},{"key":"20_CR29","doi-asserted-by":"publisher","unstructured":"Oz, H., Tuncay, G.S., Aris, A., Acar, A., Babun, L., Uluagac, S.: Ransomware over modern web browsers: a novel strain and a new defense mechanism. ACM Trans. Web 19(1) (2025). https:\/\/doi.org\/10.1145\/3708514","DOI":"10.1145\/3708514"},{"key":"20_CR30","unstructured":"Sabir, B., Ullah, F., Babar, M.A., Gaire, R.: Machine learning for detecting data exfiltration: a review (2021). https:\/\/arxiv.org\/abs\/2012.09344"},{"key":"20_CR31","unstructured":"Sophos: Sophos - cybersecurity evolved (2025). https:\/\/www.sophos.com\/en-us. Accessed 29 Mar 2025"},{"key":"20_CR32","unstructured":"Sophos: Sophos chrome security. Chrome Web Store (2025). https:\/\/chromewebstore.google.com\/detail\/sophos-chrome-security\/lkffbjbdklhachngaoeelmcgijmlicph?hl=en. Accessed 13 Feb 2026"},{"key":"20_CR33","doi-asserted-by":"crossref","unstructured":"Tari, Z., Sohrabi, N., Samadi, Y., Suaboot, J.: Data Exfiltration Threats and Prevention Techniques: Machine Learning and Memory-Based Data Security. Springer, English edn. (2023)","DOI":"10.1002\/9781119898900"},{"key":"20_CR34","doi-asserted-by":"crossref","unstructured":"Tian, Y., Liu, Y.C., Bhosale, A., Huang, L.S., Tague, P., Jackson, C.: All your screens are belong to us: attacks exploiting the html5 screen sharing API. In: IEEE Symposium on Security and Privacy (2014)","DOI":"10.1109\/SP.2014.10"},{"key":"20_CR35","unstructured":"Web Incubator Community Group: Web Incubator Community Group (WICG) (2025). https:\/\/wicg.io\/. Accessed 26 Mar 2025"},{"key":"20_CR36","unstructured":"WebKit: The File System Access API with Origin Private File System (2022). https:\/\/webkit.org\/blog\/12257\/the-file-systemaccess-api-with-origin-private-file-system\/. Accessed 26 Mar 2025"},{"key":"20_CR37","unstructured":"Weeks, M.: Internal affairs: Hacking file system access from the web (2021). https:\/\/i.blackhat.com\/USA21\/Wednesday-Handouts\/us-21-Internal-Affairs-Hacking-File-System-Access-From-The-Web.pdf. Accessed 29 Mar 2025"},{"key":"20_CR38","unstructured":"WHATWG: Fetch Standard (2025). https:\/\/fetch.spec.whatwg.org\/. Accessed 27 Mar 2025"},{"key":"20_CR39","doi-asserted-by":"crossref","unstructured":"von Zezschwitz, E., Chen, S., Stark, E.: it builds trust with the customers\u2013exploring user perceptions of the padlock icon in browser UI. In: IEEE Security and Privacy Workshops. IEEE Computer Society (2022)","DOI":"10.1109\/SPW54247.2022.9833869"}],"container-title":["Lecture Notes in Computer Science","Information Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-3018-1_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T07:26:51Z","timestamp":1784359611000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-3018-1_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819230174","9789819230181"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-3018-1_20","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"18 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACISP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australasian Conference on Information Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Perth, WA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acisp2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/acisp-conference.github.io\/acisp2026\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}