Puppetnets: Misusing Web Browsers as a Distributed Attack Infrastructure

  • Authors:
  • Spiros Antonatos;Periklis Akritidis;Vinh The Lam;Kostas G. Anagnostakis

  • Affiliations:
  • FORTH-ICS;Cambridge University;University of California;Institute for Infocomm Research (I2R)

  • Venue:
  • ACM Transactions on Information and System Security (TISSEC)
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Most of the recent work on Web security focuses on preventing attacks that directly harm the browser’s host machine and user. In this paper we attempt to quantify the threat of browsers being indirectly misused for attacking third parties. Specifically, we look at how the existing Web infrastructure (e.g., the languages, protocols, and security policies) can be exploited by malicious or subverted Web sites to remotely instruct browsers to orchestrate actions including denial of service attacks, worm propagation, and reconnaissance scans. We show that attackers are able to create powerful botnet-like infrastructures that can cause significant damage. We explore the effectiveness of countermeasures including anomaly detection and more fine-grained browser security policies.