Mitigating cross-site form history spamming attacks with domain-based ranking

1Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Modern Web browsers often provide a very useful form autocomplete feature to help users conveniently speed up their form filling process. However, browsers are generally too permissive in both saving form history data and suggesting them to users. Attackers can take advantage of this permissiveness and use malicious webpages to inject a large amount of junk or spam data into the form history database of a browser, performing invasive advertising or simply making this useful form autocomplete feature almost useless to users. In this paper, we illustrate that this type of cross-site form history spamming attacks can be feasibly achieved at least on the recent versions of Mozilla Firefox and Google Chrome browsers. We inspect the autocomplete feature implementations in open source Firefox and Chromium browsers to analyze how basic and advanced cross-site form history spamming attacks can be successful. Browser vendors are apparently taking active measures to protect against these attacks, but we explore a different approach and propose a domain-based ranking mechanism to address the problem. Our mechanism is simple, transparent to users, and easily adoptable by different browsers to complement their existing protection mechanisms. We have implemented this mechanism in Firefox 3 and verified its effectiveness. We make our Firefox 3 build available for download and verification. © 2011 Springer-Verlag.

Cite

CITATION STYLE

APA

Yue, C. (2011). Mitigating cross-site form history spamming attacks with domain-based ranking. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 6739 LNCS, pp. 104–123). https://doi.org/10.1007/978-3-642-22424-9_7

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free