Advertisement
Promo

Office applications Toolkit

Download now

Puppetnets: Misusing Web Browsers as a Distributed Attack Infrastructure

PublisherAssociation for Computing Machinery
Format2.4MB PDFDate added03 Nov 2006
Topics Web Browsers, Network Security, Security Management
Downloads11

Most of the recent work on Web security focuses on preventing attacks that directly harm the browser's host machine and user. This paper attempts to quantify the threat of browsers being indirectly misused for attacking third parties. Specifically, the paper looks at how the existing Web infrastructure (e.g., the languages, protocols, and security policies) can be exploited by malicious Web sites to remotely instruct browsers to orchestrate actions including denial of service attacks, worm propagation and reconnaissance scans. The paper shows that, depending mostly on the popularity of a malicious Web site and user browsing patterns, attackers are able to create powerful botnet-like infrastructures that can cause significant damage. The paper explores the effectiveness of counter-measures including anomaly detection and more fine-grained browser security policies.

Download now

Did you find this white paper useful?
17 out of 30 users found this white paper useful


  • Trackback
  • Clip Link

Related white papers

Improving the Web Browsing Environment for Dyslexics by Elaborating the Viewing and Reading Functionalities

Dyslexia is a disability in the brain's processing. It is characterized by difficulties in reading, writing, and retaining information in short-term memory, though it does not affect vision, hearing, or...


MSDN Webcast: Internet Explorer 8 for Developers (Level 200)

Windows Internet Explorer 8 ushers in a new wave of browser innovation from Microsoft, including Web Slices and Accelerators, while maintaining compatibility with the today's Web standards. The presenter of...


MSDN Webcast: Designing Creative DHTML, Silverlight UIs: Simple, Visualized & Intuitive (Level 300)

The presenter of this webcast shows off the new point and click Visual WebGui Control & Theme Designer. This designer joins the well known drag and drop Visual WebGui Form...


MSDN Webcast: Silverlight Controls Framework (Level 100)

The presenter of this webcast provides an overview of the Microsoft Silverlight controls and controls model. The presenter shows how to use Silverlight controls and how to make minor visual...


The Security Architecture of the Chromium Browser

Most current web browsers employ a monolithic architecture that combines "The User" and "The Web" into a single protection domain. An attacker who exploits arbitrary code execution vulnerability in such...


Leading TV and Online Sports Broadcaster Raises the Bar With Microsoft Silverlight

Founded in 1992 and based in London, Setanta Sports is a leading Internet and pay-TV sports broadcaster, operating channels in the U.K., Ireland, North America, and Australia. Setanta wanted to...


Web Technologies Help MTV Networks Create Dynamic Website and Improve Global Workflow

MTV Networks (MTVN), a division of Viacom, is one of the world's leading creators of entertainment content. In 2000, the company created ALIAS (Archive Library Information Access System), an enterprise...


Broadband Deals? Powered by Top 10 Broadband

150+ broadband packages

Compare 30+ mobile broadband deals

Mobile Broadband »
White Paper

Featured White Paper

Centrinet case study

Centrinet launched an innovative business service - Smartbunker - based on renewable energy and energy-efficient technology(efficient IBM BladeCenter servers and Cisco networking hardware), It's the UK's first managed data centre service committed to zero carbon energy. This unique proposition drastically reduces power consumption by around 60%.

Download Now

Other White Papers

Contact Centres: Optimum service at optimum cost

Getting the balance right between meeting the inbound call expectations of busy customers and...

Fact Sheet : IBMXIV Storage System

The IBM XIV® Storage System is a ground-breaking, high-end disk system, designed to support...

See All White Papers


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters