Securing User Input as a Defense Against MitB
Radhesh Krishnan K, Renuka Kumar · 2014
In MitB is a sophisticated form of attack wherein a Trojan or a bot embedded in the browser steals and tampers with legitimate user data. Online banking websites have all along been a favourite playground for these bots. While most of these sites employ multi-factor authentication, and one-time pads for transactions, even in the presence of a Secure Sockets Layer channel they are still not resilient against these attacks. This paper demonstrates how vulnerable our web accounts are to MitB attack using two significant real life examples - a Gmail account secured using Google's 2-step verification and an online banking transaction. The paper also talks about defending against the attack by identifying and securing user inputs of a system that will be the weakest link in the device or transaction authorization chain. The nature of this attack is such that they happen so silently, the user may not even notice any malicious activity and may simply disregard any unnatural behaviour as an oversight on the part of the user himself or simply a technical difficulty. Hence, what the paper also reiterates is that, as engineers of software systems, security has to be enforced on the end user when required and must not be left as an option for the tech savvy users alone.