跳到主要导航 跳到搜索 跳到主要内容

Large-scale detection of privacy leaks for BAT browsers extensions in China

  • Beihang University
  • National Computer Network Emergency Response

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Although browser extensions bring users a better experience, it creates a hidden danger of privacy leakage. A common privacy leakage detection method is realized through detecting private data transmission. However, only the unintended transmission is considered to be a privacy leak. Therefore, the real challenge is to determine whether or not the transmission is user intended. In order to address this problem, we check the rationality of private data transmission by establishing a privacy model based on classification for extensions to confirm the scope of private data that can be uploaded and domains that can be sent to. Furthermore, we present BEDS (Browser Extension Detection System), a Chromium based extension dynamic detection system. BEDS first builds a privacy model for each extension and then records the extension's network logs and browser API logs when accessing specified pages. Finally, BEDS determines whether there exists a privacy leak according to the strict privacy leakage judgment rules. We test our implementation in large scale on extensions in browsers developed by China's three major Internet companies and complete 15 months of continuous tracking. After examining a total of 14,487 extensions, 1,897 privacy leaks are identified, all results have been inspected by manual and the accuracy of BEDS is over 97%. A number of domains that illegally collect private user data are discovered and tracked. Our results show that about 47,000 Chinese IPs upload private information to suspicious servers every day.

源语言英语
主期刊名Proceedings - 2019 13th International Symposium on Theoretical Aspects of Software Engineering, TASE 2019
出版商Institute of Electrical and Electronics Engineers Inc.
57-64
页数8
ISBN(电子版)9781728133423
DOI
出版状态已出版 - 7月 2019
活动13th International Symposium on Theoretical Aspects of Software Engineering, TASE 2019 - Guilin, 中国
期限: 29 7月 201931 7月 2019

出版系列

姓名Proceedings - 2019 13th International Symposium on Theoretical Aspects of Software Engineering, TASE 2019

会议

会议13th International Symposium on Theoretical Aspects of Software Engineering, TASE 2019
国家/地区中国
Guilin
时期29/07/1931/07/19

指纹

探究 'Large-scale detection of privacy leaks for BAT browsers extensions in China' 的科研主题。它们共同构成独一无二的指纹。

引用此