View metadata, citation and similar papers at core.ac.uk brought to you by CORE provided by DigitalCommons@Kennesaw State University Kennesaw State University DigitalCommons@Kennesaw State University Faculty Publications 6-8-2014 Effective Detection of Vulnerable and Malicious Browser Extensions Hossain Shahriar Kennesaw State University,
[email protected] Komminist Weldemariam School of Computing,
[email protected] Mohammad Zulkernine School of Computing Thibaud Lutellier School of Computing Follow this and additional works at: http://digitalcommons.kennesaw.edu/facpubs Part of the Computer Sciences Commons Recommended Citation Shahriar, H., Weldemariam, K., Zulkernine, M., & Lutellier, T. (2014). Effective detection of vulnerable and malicious browser extensions. Computers & Security, 47, 66-84. This Article is brought to you for free and open access by DigitalCommons@Kennesaw State University. It has been accepted for inclusion in Faculty Publications by an authorized administrator of DigitalCommons@Kennesaw State University. For more information, please contact
[email protected]. Effective Detection of Vulnerable and Malicious Browser Extensions b d,a, d Hossain Shahriar , Komminist Weldemariam ∗, Mohammad Zulkernine , Thibaud Lutellierd a IBM Research j Africa CUEA, Langata Road, Nairobi. Kenya b Department of Computer Science, Kennesaw State University Kennesaw GA 30144, USA c Department of Computer Science, Kennesaw State University Kennesaw GA 30144, USA d School of Computing, Queen's University Kingston Ontario. Canada K7L 3N6 Abstract Unsafely coded browser extensions can compromise the security of a browser, making them attractive targets for attackers as a primary vehicle for conducting cyber-attacks. Among others, the three factors making vulnerable extensions a high-risk security threat for browsers include: i) the wide popularity of browser extensions, ii) the similarity of browser extensions with web applications, and iii) the high privilege of browser extension scripts.