Title | A DNS Security Policy for Timely Detection of Malicious Modification on Webpages |
Publication Type | Conference Paper |
Year of Publication | 2021 |
Authors | Varshney, Gaurav, Shah, Naman |
Conference Name | 2021 28th International Conference on Telecommunications (ICT) |
Keywords | Browsers, compositionality, DNS, domain name system, Human Behavior, malicious browser extensions, malicious modification, Metrics, phishing, pubcrawl, resilience, Resiliency, security, security policies, Telecommunications, Web Browser Security, web defacement, Web pages, websites |
Abstract | End users consider the data available through web as unmodified. Even when the web is secured by HTTPS, the data can be tampered in numerous tactical ways reducing trust on the integrity of data at the clients' end. One of the ways in which the web pages can be modified is via client side browser extensions. The extensions can transparently modify the web pages at client's end and can include new data to the web pages with minimal permissions. Clever modifications can be addition of a fake news or a fake advertisement or a link to a phishing website. We have identified through experimentation that such attacks are possible and have potential for serious damages. To prevent and detect such modifications we present a novel domain expressiveness based approach that uses DNS (Domain Name System) TXT records to express the Hash of important web pages that gets verified by the browsers to detect/thwart any modifications to the contents that are launched via client side malicious browser extensions or via cross site scripting. Initial experimentation suggest that the technique has potential to be used and deployed. |
DOI | 10.1109/ICT52184.2021.9511514 |
Citation Key | varshney_dns_2021 |