Title
Botnet with Browser Extensions
Abstract
Botnets are responsible for many large scale organized Internet attacks today. Along with the fight between botnet developers and defenders, the battle field has significantly evolved from traditional centralized IRC to various new approaches, aiming to make bots and command and control channel more and more stealthy. In this work, through prototype implementations, we demonstrate that browser extensions are a very effective botnet vehicle with very large installation base and the capability of accessing rich sensitive user data in the browser. The automatic update mechanism of browser extensions further offers a stealthy command and control channel between bots and a botmaster. Compared to many others, extension-based bots are more stealthy and harder to defeat since all mainstream browser architectures provide rich APIs for browser extensions to enrich users' browsing experience with insufficient consideration of malicious extensions. Via both an IE add-on and a Chrome extension, we show that attacks like email spamming, password sniffing, and DDoS are trivially feasible. Our study shows that an effective scheme is imperatively demanded to mitigate such threats.
Year
DOI
Venue
2011
10.1109/PASSAT/SocialCom.2011.25
SocialCom/PASSAT
Keywords
DocType
ISBN
command and control channel,password sniffing,online front-ends,botmaster,ie add-ons,email spamming,computer network security,browser extensions,installation base,ie add on,botnet,rich sensitive user data,internet,bot,api,chrome extension,ddos,large scale organized internet attacks,chrome extensions,centralized irc,security of data,command and control,servers,security,internet security,web pages
Conference
978-1-4577-1931-8
Citations 
PageRank 
References 
2
0.38
13
Authors
3
Name
Order
Citations
PageRank
Lei Liu113910.27
Xinwen Zhang269746.90
Songqing Chen315412.43