Vis enkel innførsel

dc.contributor.advisorGligoroski, Danilonb_NO
dc.contributor.authorThoresen, Torgeir Dahlqvistnb_NO
dc.date.accessioned2014-12-19T14:11:59Z
dc.date.available2014-12-19T14:11:59Z
dc.date.created2010-09-02nb_NO
dc.date.issued2009nb_NO
dc.identifier347117nb_NO
dc.identifierntnudaim:4634nb_NO
dc.identifier.urihttp://hdl.handle.net/11250/261636
dc.description.abstractWhile the complexity of web applications and their functionality continually increase, so do the number of opportunities for an attacker to launch successful attacks against a web application's users. In this thesis we investigate and describe clickjacking in great detail. To our knowledge, this work represent the first systematic scientific approach to assess clickjacking that also consider the attack's social consequences for users' security through an experiment and survey. We address the appearance and transparency of a clickjacking attack and present four proof of concept clickjacking attacks. Our work show how very simplistic code can be used to launch powerful clickjacking attacks. Additionally, we suggest a selection of scenarios that describe functionality likely prone to clickjacking attacks, and evaluate their impact. Our proof of concept code introduce a stateful clickjacking attack able to hijack sequences of clicks from a visitor of an attacker web page, while the functionality of the attacker web page is fully intact. In general, this shows that attackers can create fully functional web pages where possibly all clicks from a visiting user can be used for malicious purposes, while the attacker web page is updated on every interaction. Our work indicate that launching an invisible clickjacking attack indeed is possible, and many users misinterpret such an attack as unsuccessful clicks. In our experiment 4 out of 5 participants were clickjacked from a harmless attack, and a sheer 1 out of 4 noticed activity out of the ordinary while being attacked. We also show that even participants that believe themselves to be security-aware when browsing the Internet are prone to clickjacking attacks. Today no web browsers offer default protection against clickjacking attacks and scientific research on the topic is sparse. This work aims to raise the awareness of clickjacking attacks.nb_NO
dc.languageengnb_NO
dc.publisherInstitutt for telematikknb_NO
dc.subjectntnudaimno_NO
dc.subjectSIE7 kommunikasjonsteknologino_NO
dc.subjectTelematikkno_NO
dc.titleNew trends in Internet attacks: Clickjacking in detailnb_NO
dc.typeMaster thesisnb_NO
dc.source.pagenumber162nb_NO
dc.contributor.departmentNorges teknisk-naturvitenskapelige universitet, Fakultet for informasjonsteknologi, matematikk og elektroteknikk, Institutt for telematikknb_NO


Tilhørende fil(er)

Thumbnail
Thumbnail
Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel