{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,29]],"date-time":"2025-08-29T10:07:02Z","timestamp":1756462022400},"reference-count":50,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2018,12,13]],"date-time":"2018-12-13T00:00:00Z","timestamp":1544659200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2019,8]]},"DOI":"10.1007\/s10207-018-0423-3","type":"journal-article","created":{"date-parts":[[2018,12,13]],"date-time":"2018-12-13T09:50:25Z","timestamp":1544694625000},"page":"481-504","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["You click, I steal: analyzing and detecting click hijacking attacks in web pages"],"prefix":"10.1007","volume":"18","author":[{"given":"Anil","family":"Saini","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Manoj Singh","family":"Gaur","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vijay","family":"Laxmi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,12,13]]},"reference":[{"key":"423_CR1","unstructured":"Grossman, J.: Clickjacking-owasp appsec talk (2008). \n                    http:\/\/blog.jeremiahgrossman.com\/2008\/09\/cancelled-clickjackingowasp-appsec.html\n                    \n                  . Accessed 12 Mar 2016"},{"key":"423_CR2","unstructured":"Hansen, R., Grossman, J.: Clickjacking (2008)"},{"key":"423_CR3","unstructured":"Niemietz, M.: Ui redressing: attacks and countermeasures revisited. In: CONFidence, 2011 (2011)"},{"key":"423_CR4","unstructured":"Stone, P.: Next generation clickjacking. media. blackhat. com\/bh-eu-10\/presentations. In: Stone\/BlackHat-EU-2010-Stone-Next-Generation-Clickjacking-slides.pdf 3 (2010)"},{"key":"423_CR5","doi-asserted-by":"crossref","unstructured":"Vadrevu, P., Liu, J., Li, B., Rahbarinia, B., Lee, K.H., Perdisci, R.: Enabling reconstruction of attacks on users via efficient browsing snapshots (2017)","DOI":"10.14722\/ndss.2017.23100"},{"key":"423_CR6","doi-asserted-by":"crossref","unstructured":"Selim, H., Tayeb, S., Kim, Y., Zhan, J., Pirouz, M.: Vulnerability analysis of iframe attacks on websites. In: Proceedings of the The 3rd Multidisciplinary International Social Networks Conference on SocialInformatics 2016, Data Science 2016, p.\u00a045. ACM (2016)","DOI":"10.1145\/2955129.2955180"},{"key":"423_CR7","unstructured":"Zalewski, M.: Dealing with ui redress vulnerabilities inherent to the current web (2009). \n                    http:\/\/lists.whatwg.org\/pipermail\/whatwgwhatwg.org\/2008-September\/016284.html\n                    \n                  . Accessed 6 Aug 2014"},{"key":"423_CR8","unstructured":"Zalewski, M.: Strokejacking (2010). \n                    http:\/\/seclists.org\/fulldisclosure\/2010\/Mar\/232\n                    \n                  . Accessed 11 Nov 2014"},{"key":"423_CR9","unstructured":"Bordi, E.: Proof of concept-cursorjacking (2010)"},{"key":"423_CR10","unstructured":"Huang, L.-S., Moshchuk, A., Wang, H.J., Schecter, S., Jackson, C.: Clickjacking: Attacks and Defenses. In: USENIX Security Symposium, pp. 413\u2013428 (2012)"},{"key":"423_CR11","unstructured":"Vasile C., HTML5 Introduction-What is HTML5 Capable of, Features, and Resources.In: MJ Burns, Producer, & 1stWebDesigner Ltd) Retrieved May 28 (2012): 2013"},{"key":"423_CR12","volume-title":"Yale C\/Aim Web Style Guide","author":"P Lynch","year":"1997","unstructured":"Lynch, P., Horton, S.: Yale C\/Aim Web Style Guide. Yale Center for Advanced Instructional Media, Yale (1997)"},{"key":"423_CR13","volume-title":"Scalable Vector Graphics (SVG) 10 Specification","author":"J Ferraiolo","year":"2000","unstructured":"Ferraiolo, J., Jun, F., Jackson, D.: Scalable Vector Graphics (SVG) 10 Specification. iUniverse, Bloomington (2000)"},{"key":"423_CR14","volume-title":"SVG Essentials: Producing Scalable Vector Graphics with XML","author":"JD Eisenberg","year":"2002","unstructured":"Eisenberg, J.D.: SVG Essentials: Producing Scalable Vector Graphics with XML. O\u2019Reilly Media Inc., Newton (2002)"},{"key":"423_CR15","volume-title":"SVG Unleashed","author":"A Watt","year":"2002","unstructured":"Watt, A.: SVG Unleashed. Pearson Education, London (2002)"},{"key":"423_CR16","unstructured":"Ayars, J., Bulterman, D., Cohen, A., Day, K., Hodge, E., Hoschka, P., Hyche, E., Jourdan, M., Kim, M., Kubota, K., et\u00a0al.: Synchronized multimedia integration language (smil 2.0). World Wide Web Consort. Recomm. 7, 514 (2001)"},{"key":"423_CR17","unstructured":"Mozilla\u00a0Developer Network. Gecko (2011)"},{"key":"423_CR18","unstructured":"XSS Filter Evasion\u00a0Cheat Sheet: Retrieved June 20, 2013 from The Open Web Application Security Project. \n                    https:\/\/www.owasp.org\/index.php\n                    \n                   (2013)"},{"key":"423_CR19","doi-asserted-by":"crossref","unstructured":"Johari, R., Sharma, P.: A survey on web application vulnerabilities (sqlia, xss) exploitation and security engine for sql injection. In: 2012 International Conference on Communication Systems and Network Technologies (CSNT), pp. 453\u2013458. IEEE (2012)","DOI":"10.1109\/CSNT.2012.104"},{"key":"423_CR20","unstructured":"Lerner, B.S., Carroll, M.J., Kimmel, D.P., La\u00a0Vallee, H.Q.-D., Krishnamurthi, S.: Modeling and reasoning about dom events. In: Proceedings of the 3rd USENIX Conference on Web Application Development, pp. 1\u20131. USENIX Association (2012)"},{"key":"423_CR21","unstructured":"Blatz, J.: Csrf: Attack and Defense. McAfee\u00ae Foundstone\u00ae Professional Services, White Paper (2007)"},{"issue":"3","key":"423_CR22","first-page":"9","volume":"28","author":"SH Kim","year":"2013","unstructured":"Kim, S.H., Lee, S.H., Jin, S.H.: Active phishing attack and its countermeasures. Electron. Telecommun. Trends 28(3), 9\u201318 (2013)","journal-title":"Electron. Telecommun. Trends"},{"key":"423_CR23","unstructured":"Kaplan, R.M., Martin, K., John, M. Finite state machine data storage where data transition is accomplished without the use of pointers. U.S. Patent 5,450,598 (1995)"},{"key":"423_CR24","doi-asserted-by":"crossref","unstructured":"Balduzzi, M., Egele, M., Kirda, E., Balzarotti, D., Kruegel, C.: A solution for the automated detection of clickjacking attacks. In: Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, pp. 135\u2013144. ACM (2010)","DOI":"10.1145\/1755688.1755706"},{"key":"423_CR25","unstructured":"Lekies, S., Heiderich, M., Appelt, D., Holz, T., Johns, M.: On the fragility and limitations of current browser-provided clickjacking protection schemes. In: WOOT, pp. 53\u201363 (2012)"},{"key":"423_CR26","first-page":"6","volume":"2","author":"G Rydstedt","year":"2010","unstructured":"Rydstedt, G., Bursztein, E., Boneh, D., Jackson, C.: Busting frame busting: a study of clickjacking vulnerabilities at popular sites. IEEE Oakl. Web 2, 6 (2010)","journal-title":"IEEE Oakl. Web"},{"key":"423_CR27","unstructured":"Nepomnyashy, M.: Protecting Applications Against Clickjacking with F5 LTM. SANS Institute InfoSec Reading Room (2013)"},{"key":"423_CR28","doi-asserted-by":"crossref","unstructured":"Shahriar, H., Devendran, V.K., Haddad, H.: Proclick: a framework for testing clickjacking attacks in web applications. In: Proceedings of the 6th International Conference on Security of Information and Networks, pp. 144\u2013151. ACM (2013)","DOI":"10.1145\/2523514.2523538"},{"key":"423_CR29","unstructured":"Aharonovsky, G.: Malicious camera spying using clickjacking (2008)"},{"key":"423_CR30","doi-asserted-by":"crossref","unstructured":"Shamsi, J.A., Hameed, S., Rahman, W., Zuberi, F., Altaf, K., Amjad, A.: Clicksafe: providing security against clickjacking attacks. In: 2014 IEEE 15th International Symposium on High-Assurance Systems Engineering (HASE), pp. 206\u2013210. IEEE (2014)","DOI":"10.1109\/HASE.2014.36"},{"key":"423_CR31","unstructured":"Clickjacking defense cheatsheet: \n                    https:\/\/www.owasp.org\/index.php\/Clickjacking_Defense_Cheat_Sheet\n                    \n                  . Accessed 15 Oct 2017"},{"key":"423_CR32","unstructured":"Aboukhadijeh, F.: How to: spy on the webcams of your website visitors (2011)"},{"key":"423_CR33","unstructured":"Maone, G. NoScript Firefox Extension. [software] (2006)"},{"key":"423_CR34","volume-title":"Document Object Model","author":"J Marini","year":"2002","unstructured":"Marini, J.: Document Object Model. McGraw-Hill Inc., New York (2002)"},{"key":"423_CR35","volume-title":"jQuery in Action","author":"B Bibeault","year":"2008","unstructured":"Bibeault, B., Kats, Y.: jQuery in Action. Dreamtech Press, New Delhi (2008)"},{"key":"423_CR36","unstructured":"Alexa internet, inc. alexa - top sites by category: (2014). \n                    http:\/\/www.alexa.com\/topsites\/category\/Top\/\n                    \n                  . Accessed 24 Dec 2014"},{"key":"423_CR37","unstructured":"Malware domain list: (2014). \n                    http:\/\/www.malwaredomainlist.com\/\n                    \n                  . Accessed 24 Dec 2014"},{"key":"423_CR38","unstructured":"Phishtank domain list: (2014). \n                    http:\/\/www.phishtank.com\/\n                    \n                  . Accessed 24 Dec 2014"},{"key":"423_CR39","unstructured":"Mozilla foundation: (2013). \n                    https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=154957\n                    \n                  . Accessed 24 Dec 2014"},{"issue":"6","key":"423_CR40","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1145\/1516046.1516066","volume":"52","author":"A Barth","year":"2009","unstructured":"Barth, A., Jackson, C., Mitchell, J.C.: Securing frame communication in browsers. Commun. ACM 52(6), 83\u201391 (2009)","journal-title":"Commun. ACM"},{"key":"423_CR41","unstructured":"Zalewski, M.: Browser security handbook. Google Code (2010)"},{"key":"423_CR42","first-page":"15347","volume":"24","author":"V Chebyshev","year":"2014","unstructured":"Chebyshev, V., Unuchek, R.: Mobile malware evolution: 2013. Kaspersky Lab ZAOs SecureList 24, 15347 (2014)","journal-title":"Kaspersky Lab ZAOs SecureList"},{"key":"423_CR43","unstructured":"Unuchek, R.: Svpeng android malware targets google play with fake credit card window. \n                    http:\/\/securelist.com\/blog\/incidents\/63746\/latestversion-of-svpengtargets-users-in-us\/\n                    \n                  . Accessed Nov 2017"},{"key":"423_CR44","doi-asserted-by":"crossref","unstructured":"Fernandes, E., Chen, Q.A., Paupore, J., Essl, G., Halderman, J.A., Mao, Z.M., Prakash, A.: Android ui deception revisited: Attacks and defenses. In: International Conference on Financial Cryptography and Data Security, pp. 41\u201359. Springer (2016)","DOI":"10.1007\/978-3-662-54970-4_3"},{"key":"423_CR45","unstructured":"Close, T.: Web-key: mashing with permission. In: Proceedings of Web, vol.\u00a02. Citeseer (2008)"},{"issue":"2","key":"423_CR46","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1145\/502152.502153","volume":"1","author":"DM Kristol","year":"2001","unstructured":"Kristol, D.M.: Http cookies: standards, privacy, and politics. ACM Trans. Internet Technol. (TOIT) 1(2), 151\u2013198 (2001)","journal-title":"ACM Trans. Internet Technol. (TOIT)"},{"key":"423_CR47","unstructured":"Kotowicz, K.: Cursorjacking again (2012). \n                    http:\/\/blog.kotowicz.net\/2012\/01\/cursorjacking-again.html\n                    \n                  . Accessed 6 Sept 2014"},{"key":"423_CR48","doi-asserted-by":"crossref","unstructured":"Ross, D., Gondrom, T.: Http header field x-frame-options (2013)","DOI":"10.17487\/rfc7034"},{"key":"423_CR49","doi-asserted-by":"crossref","unstructured":"Tang, S., Dautenhahn, N., King, S.T.: Fortifying web-based applications automatically. In: Proceedings of the 18th ACM Conference on Computer and Communications Security, pp. 615\u2013626. ACM (2011)","DOI":"10.1145\/2046707.2046777"},{"key":"423_CR50","doi-asserted-by":"crossref","unstructured":"Chandra, R., Kim, T., Shah, M., Narula, N., Zeldovich, N.: Intrusion recovery for database-backed web applications. In: Proceedings of the Twenty-Third ACM Symposium on Operating Systems Principles, pp. 101\u2013114. ACM (2011)","DOI":"10.1145\/2043556.2043567"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-018-0423-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-018-0423-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-018-0423-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,12,13]],"date-time":"2019-12-13T00:06:28Z","timestamp":1576195588000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-018-0423-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,12,13]]},"references-count":50,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2019,8]]}},"alternative-id":["423"],"URL":"https:\/\/doi.org\/10.1007\/s10207-018-0423-3","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,12,13]]},"assertion":[{"value":"13 December 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}