Doctoral thesis (Dissertations and theses)
An Empirical Study of Browsers' Evolution Impact on Security and Privacy
Abgrall, Erwan
2014
 

Files


Full Text
thesis.pdf
Publisher postprint (1.97 MB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Web; Security; XSS; Browser; Attack Surface; Fingerprinting
Abstract :
[en] Web success is associated with the expansion of web interfaces in software. They have replaced many thick-clients and command-line interfaces. HTML is now a widely adopted generic user-interface description language. The cloud-computing trend set browsers in a central position, handling all our personal and professional information. Online banking and e-commerce are the sources of an attractive cash flow for online thefts, and all this personal information is sold on black markets. Unsurprisingly, web browsers are consequently the favorite targets of online attacks. The fierce competition between browser vendors is associated with a features race, leading to partial implementation of W3C norms, and non-standard features. It resulted in a fast release pace of new browser versions over these last years. While positively perceived by users, such competition can have a negative impact on browser security and user privacy. This increasing number of features and the discrepancies between browser vendors' implementations facilitate the attacker task for cross site scripting(XSS) and drive-by download attacks. Coming to the overall objectives of a research leading to the better understandings of browser's role in security, this thesis provides an instrument to understand XSS attack vectors, categorize them, evaluate the exposure of web browsers against XSS and may eventually open the field, but this is beyond the scope of this thesis, to a new strategy to detect future client-side attacks, however this last point is beyond the scope of this thesis.
Disciplines :
Computer science
Author, co-author :
Abgrall, Erwan;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Language :
English
Title :
An Empirical Study of Browsers' Evolution Impact on Security and Privacy
Defense date :
23 September 2014
Number of pages :
148
Institution :
Unilu - University of Luxembourg, Luxembourg, Luxembourg
Degree :
Docteur en Informatique
Promotor :
President :
Funders :
Kereval
Available on ORBilu :
since 14 November 2014

Statistics


Number of views
155 (7 by Unilu)
Number of downloads
3400 (0 by Unilu)

Bibliography


Similar publications



Contact ORBilu