The Analysis of HTTPS Privacy Protection Based on Malicious Code Injection
Zeyan Liu, Jianshan Pen · 2020
HTTPS protocol is utilized to protect personal privacy in network communication by man-in-the-middle attacks. However, after the browser is attacked, this protection mechanism will be destroyed. This paper analyzes the vulnerability of https protocol under two scenarios of operating system and network data transmission. Based on the untrusted situation, the possibility of implementing HTTPS protocol injection and page injection on the browser side was analyzed. A traffic monitoring and detection scheme based on dynamic rules is proposed, which can effectively detect whether the browser is injected with malicious code. False positive is less than 10%.