{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T03:07:12Z","timestamp":1781060832582,"version":"3.54.1"},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2019,6,11]],"date-time":"2019-06-11T00:00:00Z","timestamp":1560211200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2019,6,11]],"date-time":"2019-06-11T00:00:00Z","timestamp":1560211200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100000781","name":"European Research Council","doi-asserted-by":"publisher","award":["ERC Starting Grant (No. 306994)"],"award-info":[{"award-number":["ERC Starting Grant (No. 306994)"]}],"id":[{"id":"10.13039\/501100000781","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2019,12]]},"DOI":"10.1007\/s10207-019-00442-1","type":"journal-article","created":{"date-parts":[[2019,6,11]],"date-time":"2019-06-11T16:03:07Z","timestamp":1560268987000},"page":"801-814","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":21,"title":["DOMtegrity: ensuring web page integrity against malicious browser extensions"],"prefix":"10.1007","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5172-2957","authenticated-orcid":false,"given":"Ehsan","family":"Toreini","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siamak F.","family":"Shahandashti","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maryam","family":"Mehrnezhad","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Feng","family":"Hao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,6,11]]},"reference":[{"key":"442_CR1","doi-asserted-by":"crossref","unstructured":"Adham, M., Azodi, A., Desmedt, Y., Karaolis, I.: How to attack two-factor authentication internet banking. In: International Conference on Financial Cryptography and Data Security, pp. 322\u2013328. Springer (2013)","DOI":"10.1007\/978-3-642-39884-1_27"},{"key":"442_CR2","volume-title":"The Browser Hacker\u2019s Handbook","author":"W Alcorn","year":"2014","unstructured":"Alcorn, W., Frichot, C., Orru, M.: The Browser Hacker\u2019s Handbook. Wiley, New York (2014)"},{"key":"442_CR3","unstructured":"Arbaugh, W.A., Farber, D.J., Smith, J.M.: A secure and reliable bootstrap architecture. In: 1997 IEEE Symposium on Security and Privacy, 1997. Proceedings, pp. 65\u201371. IEEE (1997)"},{"key":"442_CR4","unstructured":"Bandhakavi, S., King, S.T., Madhusudan, P., Winslett, M.: Vex: vetting browser extensions for security vulnerabilities. In: USENIX Security Symposium, vol. 10, pp. 339\u2013354 (2010)"},{"key":"442_CR5","unstructured":"Chrome Developers: Webrequest API. \n                    https:\/\/developer.chrome.com\/extensions\/webRequest\n                    \n                  . Accessed Mar 2018"},{"key":"442_CR6","unstructured":"Dhawan, M., Ganapathy, V.: Analyzing information flow in Javascript-based browser extensions. In: Computer Security Applications Conference, 2009. ACSAC\u201909. Annual, pp. 382\u2013391. IEEE (2009)"},{"issue":"1","key":"442_CR7","doi-asserted-by":"publisher","first-page":"29","DOI":"10.4018\/jaci.2012010103","volume":"4","author":"T Dougan","year":"2012","unstructured":"Dougan, T., Curran, K.: Man in the browser attacks. Int. J. Ambient Comput. Intell. (IJACI) 4(1), 29\u201339 (2012)","journal-title":"Int. J. Ambient Comput. Intell. (IJACI)"},{"key":"442_CR8","unstructured":"GBHackers on Security: Droidclub botnet via malicious chrome extensions that affect more than half a million users. \n                    https:\/\/gbhackers.com\/droidclub-botnet-chrome-extensions\/\n                    \n                  . Accessed Mar 2018"},{"key":"442_CR9","unstructured":"Gibbs, S.: Google pulls malware Twitter and Feedly extensions for Chrome. The Guardian, 20 Jan 2014. \n                    http:\/\/www.theguardian.com\/technology\/2014\/jan\/20\/google-malware-twitter-feedly-chrome-browser\n                    \n                  . Accessed Apr 2019 (2014)"},{"key":"442_CR10","unstructured":"Google Chrome: Work in isolated worlds. \n                    https:\/\/developer.chrome.com\/extensions\/content_scripts#isolated_worldh\n                    \n                  . Accessed Sept 2018"},{"key":"442_CR11","doi-asserted-by":"crossref","unstructured":"Guha, A., Fredrikson, M., Livshits, B., Swamy, N.: Verified security for browser extensions. In: 2011 IEEE Symposium on Security and Privacy, pp. 115\u2013130. IEEE (2011)","DOI":"10.1109\/SP.2011.36"},{"key":"442_CR12","doi-asserted-by":"crossref","unstructured":"Heiderich, M., Frosch, T., Holz, T.: Iceshield: detection and mitigation of malicious websites with a frozen dom. In: International Workshop on Recent Advances in Intrusion Detection, pp. 281\u2013300. Springer (2011)","DOI":"10.1007\/978-3-642-23644-0_15"},{"key":"442_CR13","unstructured":"Jagpal, N., Dingle, E., Gravel, J.P., Mavrommatis, P., Provos, N., Rajab, M.A., Thomas, K.: Trends and lessons from three years fighting malicious extensions. In: 24th USENIX Security Symposium (USENIX Security 15), pp. 579\u2013593 (2015)"},{"key":"442_CR14","unstructured":"Kapravelos, A., Grier, C., Chachra, N., Kruegel, C., Vigna, G., Paxson, V.: Hulk: eliciting malicious behavior in browser extensions. In: 23rd USENIX Security Symposium (USENIX Security 14), pp. 641\u2013654 (2014)"},{"key":"442_CR15","doi-asserted-by":"crossref","unstructured":"Kashyap, V., Hardekopf, B.: Security signature inference for Javascript-based browser addons. In: Proceedings of Annual IEEE\/ACM International Symposium on Code Generation and Optimization, p. 219. ACM (2014)","DOI":"10.1145\/2544137.2544149"},{"key":"442_CR16","unstructured":"Liu, L., Zhang, X., Yan, G., Chen, S.: Chrome extensions: threat analysis and countermeasures. In: NDSS (2012)"},{"key":"442_CR17","doi-asserted-by":"crossref","unstructured":"Marouf, S., Shehab, M.: Towards improving browser extension permission management and user awareness. In: 2012 8th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), pp. 695\u2013702. IEEE (2012)","DOI":"10.4108\/icst.collaboratecom.2012.250642"},{"key":"442_CR18","unstructured":"Mozilla: Statistics dashboard. \n                    https:\/\/addons.mozilla.org\/en-US\/statistics\n                    \n                  . Accessed Mar 2018"},{"issue":"1","key":"442_CR19","first-page":"18","volume":"3","author":"K Patil","year":"2017","unstructured":"Patil, K.: Isolating malicious content scripts of browser extensions. Int. J. Inf. Priv. Secur. Integr. 3(1), 18\u201337 (2017)","journal-title":"Int. J. Inf. Priv. Secur. Integr."},{"issue":"4","key":"442_CR20","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1109\/MSP.2018.3111249","volume":"16","author":"R Perrotta","year":"2018","unstructured":"Perrotta, R., Hao, F.: Botnet in the browser: understanding threats caused by malicious browser extensions. IEEE Secur. Priv. 16(4), 66\u201381 (2018)","journal-title":"IEEE Secur. Priv."},{"key":"442_CR21","first-page":"31","volume":"8","author":"C Reis","year":"2008","unstructured":"Reis, C., Gribble, S.D., Kohno, T., Weaver, N.C.: Detecting in-flight page changes with web tripwires. NSDI 8, 31\u201344 (2008)","journal-title":"NSDI"},{"issue":"5","key":"442_CR22","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/1551644.1556050","volume":"7","author":"C Reis","year":"2009","unstructured":"Reis, C., Barth, A., Pizano, C.: Browser security: lessons from google chrome. Queue 7(5), 3 (2009)","journal-title":"Queue"},{"key":"442_CR23","doi-asserted-by":"crossref","unstructured":"Saini, A., Gaur, M.S., Laxmi, V., Singhal, T., Conti, M.: Privacy leakage attacks in browsers by colluding extensions. In: International Conference on Information Systems Security, pp. 257\u2013276. Springer (2014)","DOI":"10.1007\/978-3-319-13841-1_15"},{"issue":"3","key":"442_CR24","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1007\/s11416-007-0078-5","volume":"4","author":"M Ter Louw","year":"2008","unstructured":"Ter Louw, M., Lim, J.S., Venkatakrishnan, V.N.: Enhancing web browser security against malware extensions. J. Comput. Virol. 4(3), 179\u2013195 (2008)","journal-title":"J. Comput. Virol."},{"key":"442_CR25","unstructured":"W3C: W3c dom4. \n                    https:\/\/www.w3.org\/TR\/dom\/\n                    \n                  . Accessed Mar 2018"},{"key":"442_CR26","unstructured":"W3C Browser Extension Community Group: Browser extensions (report 23 July 2017). \n                    https:\/\/browserext.github.io\/browserext\/\n                    \n                  . Accessed Mar 2018"},{"key":"442_CR27","doi-asserted-by":"crossref","unstructured":"Wang, L., Xiang, J., Jing, J., Zhang, L.: Towards fine-grained access control on browser extensions. In: International Conference on Information Security Practice and Experience, pp. 158\u2013169. Springer (2012)","DOI":"10.1007\/978-3-642-29101-2_11"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-019-00442-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-019-00442-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-019-00442-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,6,9]],"date-time":"2020-06-09T23:16:42Z","timestamp":1591744602000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-019-00442-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,6,11]]},"references-count":27,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2019,12]]}},"alternative-id":["442"],"URL":"https:\/\/doi.org\/10.1007\/s10207-019-00442-1","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,6,11]]},"assertion":[{"value":"11 June 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"In this research, we have designed cyber attacks on personal banking websites. These experiments have been performed against the author\u2019s bank accounts, and the money was only transferred between these accounts. All the experiments were approved by Newcastle University\u2019s Ethics Committee.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical standard"}}]}}