Protecting Users from Compromised Browsers and Form Grabbers

Sirvan Almasi, William J. Knottenbelt · 2020

With the increasing use of the internet we are always in reach of a browser and a website.Users are continuously feeding sensitive information (such as passwords, personal and credit card information) to websites.These browsers and websites are susceptible to attacks from compromised clientside code, the browser and the operating system itself.Such threats emanate from Man-in-the-Browser (MitB) malware and form grabbers that are able to steal information from HTML forms and manipulate the forms at the cost of the user, resulting in the loss of sensitive information and financial costs.Whilst defensive techniques such as detection and prevention have their own merits, an out-of-band system can have superior security and user experience benefits.In this paper we explore the idea of circumventing the threats through a mobile phone-based system that can protect the user from compromised browsers and form grabbers.We build on the work of deeID, a blockchain-based and out-of-band identification and authentication system.Our contributions are the design of an out-of-band system dubbed FormL3SS, a standardised messaging for information request and the novel combination of existing techniques with a blockchainbased identity system.Our implementation of FormL3SS demonstrates the capabilities of sending data securely to a trusted server.

Read the paper · More papers on PaperTik