Title :
Botnet with Browser Extensions
Author :
Liu, Lei ; Zhang, Xinwen ; Chen, Songqing
Author_Institution :
Dept. of Comput. Sci., George Mason Univ., Fairfax, VA, USA
Abstract :
Botnets are responsible for many large scale organized Internet attacks today. Along with the fight between botnet developers and defenders, the battle field has significantly evolved from traditional centralized IRC to various new approaches, aiming to make bots and command and control channel more and more stealthy. In this work, through prototype implementations, we demonstrate that browser extensions are a very effective botnet vehicle with very large installation base and the capability of accessing rich sensitive user data in the browser. The automatic update mechanism of browser extensions further offers a stealthy command and control channel between bots and a botmaster. Compared to many others, extension-based bots are more stealthy and harder to defeat since all mainstream browser architectures provide rich APIs for browser extensions to enrich users´ browsing experience with insufficient consideration of malicious extensions. Via both an IE add-on and a Chrome extension, we show that attacks like email spamming, password sniffing, and DDoS are trivially feasible. Our study shows that an effective scheme is imperatively demanded to mitigate such threats.
Keywords :
Internet; computer network security; online front-ends; security of data; API; Chrome extension; DDoS; IE add on; botmaster; botnet; browser extensions; centralized IRC; email spamming; installation base; large scale organized Internet attacks; password sniffing; rich sensitive user data; Browsers; Command and control systems; Electronic mail; Internet; Security; Servers; Web pages; Chrome extensions; IE add-ons; bot; command and control channel;
Conference_Titel :
Privacy, Security, Risk and Trust (PASSAT) and 2011 IEEE Third Inernational Conference on Social Computing (SocialCom), 2011 IEEE Third International Conference on
Conference_Location :
Boston, MA
Print_ISBN :
978-1-4577-1931-8
DOI :
10.1109/PASSAT/SocialCom.2011.25