Analysis of Clickjacking Attacks and An Effective Defense Scheme for Android Devices

被引:0
|
作者
Wu, Longfei [1 ]
Brandt, Benjamin [1 ]
Du, Xiaojiang [1 ]
Ji, Bo [1 ]
机构
[1] Temple Univ, Dept Comp & Informat Sci, Philadelphia, PA 19122 USA
来源
2016 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS) | 2016年
关键词
Android; security; clickjacking;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Smartphones bring users lots of convenience by integrating all useful functions people may need. While users are spending more time on their phones, have they ever questioned of being spoofed by the phone they are interacting with? This paper conducts a thorough study of the mobile clickjacking attacks. We first present how the clickjacking attack works and the key points to remain undiscovered. Then, we evaluate its potential threats by exploring the feasibility of launching clickjacking attacks on various UIs, including system app windows, 3rd-party app windows, and other system UIs. Finally, we propose a system-level defense scheme against clickjacking attacks on Android platform, which requires no user or developer effort and is compatible with existing apps. The performance of the countermeasure is evaluated with extensive experiments. The results show that our scheme can effectively prevent clickjacking attacks with only a minor impact to the system.
引用
收藏
页码:55 / 63
页数:9
相关论文
共 50 条
  • [21] Forensic Analysis of Android Mobile Devices
    Rao, V. Venkateswara
    Chakravarthy, A. S. N.
    2016 INTERNATIONAL CONFERENCE ON RECENT ADVANCES AND INNOVATIONS IN ENGINEERING (ICRAIE), 2016,
  • [22] Effective Defense Schemes for Phishing Attacks on Mobile Computing Platforms
    Wu, Longfei
    Du, Xiaojiang
    Wu, Jie
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2016, 65 (08) : 6678 - 6691
  • [23] Towards Effective Defense against Pollution Attacks on Network Coding
    Zhu, Donghai
    Yang, Xinyu
    Yu, Wei
    2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012,
  • [24] MAEDefense: An Effective Masked AutoEncoder Defense against Adversarial Attacks
    Lyu, Wanli
    Wu, Mengjiang
    Yin, Zhaoxia
    Luo, Bin
    2023 ASIA PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE, APSIPA ASC, 2023, : 1915 - 1922
  • [25] ONION: A Simple and Effective Defense Against Textual Backdoor Attacks
    Qi, Fanchao
    Chen, Yangyi
    Li, Mukai
    Yao, Yuan
    Liu, Zhiyuan
    Sun, Maosong
    2021 CONFERENCE ON EMPIRICAL METHODS IN NATURAL LANGUAGE PROCESSING (EMNLP 2021), 2021, : 9558 - 9566
  • [26] An Effective Android Software Reinforcement Scheme Based on Online Key
    Xu, Junfeng
    Zhang, Li
    Yang, Luo
    Mao, Ye
    Shi, Xiaolong
    PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 1544 - 1548
  • [27] An Effective Access Control Scheme for Preventing Permission Leak in Android
    Wu, Longfei
    Du, Xiaojiang
    Zhang, Hongli
    2015 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2015, : 57 - 61
  • [28] WEBTRAP: A Dynamic Defense Scheme Against Economic Denial of Sustainability Attacks
    Wang, Huangxin
    Xi, Zhonghua
    Li, Fei
    Chen, Songqing
    2017 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2017, : 55 - 63
  • [29] An On-Demand Defense Scheme Against DNS Cache Poisoning Attacks
    Wang, Zheng
    Yu, Shui
    Rose, Scott
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2017, 2018, 238 : 793 - 807
  • [30] Learning an Effective Charging Scheme for Mobile Devices
    Liu, Tang
    Wu, Baijun
    Xu, Wenzheng
    Cao, Xianbo
    Peng, Jian
    Wu, Hongyi
    2020 IEEE 34TH INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM IPDPS 2020, 2020, : 202 - 211