[Home ] [Archive]   [ فارسی ]  
:: Main :: About :: Current Issue :: Archive :: Search :: Submit :: Contact ::
Main Menu
Home::
Journal Information::
Articles archive::
For Authors::
For Reviewers::
Registration::
Site Facilities::
Indexing::
Contact us::
::
Search in website

Advanced Search
..
Receive site information
Enter your Email in the following box to receive the site news and information.
..
Print ISSN
Print ISSN: 2476-3047
..
:: Volume 11, Issue 1 (9-2022) ::
منادی 2022, 11(1): 59-66 Back to browse issues page
A Tool for Detecting Man in the Browser (MitB) Attacks using Dynamic Analysis of Web Pages
Majid Iranpour Mobarakeh * , Behrouz Tork Ladani
Model Based Security Analysis (MBSA) Research Group, Faculty of Computer Engineering, University of Isfahan, Isfahan, Iran
Abstract:   (2096 Views)
Detection of browser attacks is considered a serious challenge in today’s web applications. Man in the Browser (MitB) attack is an important type of these attacks that can lead to changes in web page contents, interference in network traffic, session hijacking, and user information theft by using Trojans. In this paper, an efficient tool for real-time detection of MitB attacks through dynamic analysis of web pages based on the description of attack patterns is presented. The advantage of the proposed tool is that it is not limited to identifying one or more specific attacks and the identification method code is not embedded in the tool, but the patterns of different attacks are specified separately. In order to evaluate the presented tool, two vulnerable web services provided by OWASP, which have a wide range of known vulnerabilities, were used along with the BeEF penetration test framework, and a set of MitB attacks were practically implemented and evaluated by the tool. The same tests were performed using three other similar tools and compared with the developed tool. In addition to the superiority of the presented tool in terms of the independence of attack descriptions from the tool itself, the results show that the accuracy and readability of its diagnosis are better than similar tools.
Keywords: MitB attacks, malware, malware detection, dynamic analysis
Full-Text [PDF 1210 kb]   (446 Downloads)    
Type of Study: Research Article | Subject: Special
Received: 2023/02/13 | Accepted: 2022/09/1 | Published: 2022/09/1
Send email to the article author

Add your comments about this article
Your username or Email:

CAPTCHA


XML   Persian Abstract   Print


Download citation:
BibTeX | RIS | EndNote | Medlars | ProCite | Reference Manager | RefWorks
Send citation to:

Iranpour Mobarakeh M, Tork Ladani B. A Tool for Detecting Man in the Browser (MitB) Attacks using Dynamic Analysis of Web Pages. منادی 2022; 11 (1) :59-66
URL: http://monadi.isc.org.ir/article-1-221-en.html


Rights and permissions
Creative Commons License This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Volume 11, Issue 1 (9-2022) Back to browse issues page
دوفصل نامه علمی  منادی امنیت فضای تولید و تبادل اطلاعات( افتا) Biannual Journal Monadi for Cyberspace Security (AFTA)
Persian site map - English site map - Created in 0.05 seconds with 39 queries by YEKTAWEB 4660