• LOGIN
Repository logo

BORIS Portal

Bern Open Repository and Information System

  • Publication
  • Projects
  • Funding
  • Research Data
  • Organizations
  • Researchers
  • LOGIN
Repository logo
Unibern.ch
  1. Home
  2. Publications
  3. Stopping DNS Rebinding Attacks in the Browser
 

Stopping DNS Rebinding Attacks in the Browser

Options
  • Details
BORIS DOI
10.48350/154522
Date of Publication
2021
Publication Type
Conference Paper
Division/Institute

Institut für Informat...

Author
Hazhirpasand Barkadehi, Mohammadreza
Institut für Informatik (INF)
Ale Ebrahim, Arash
Nierstrasz, Oscar
Institut für Informatik (INF)
Subject(s)

000 - Computer scienc...

500 - Science::510 - ...

Language
English
Publisher DOI
10.5220/0010310705960603
Uncontrolled Keywords

scg-pub security snf-...

Description
DNS rebinding attacks circumvent the same-origin policy of browsers and severely jeopardize user privacy. Although recent studies have shown that DNS rebinding attacks pose severe security threats to users, up to now little effort has been spent to assess the effectiveness of known solutions to prevent such attacks. We have carried out such a study to assess the protective measures proposed in prior studies. We found that none of the recommended techniques can entirely halt this attack due to various factors, e.g., network layer encryption renders packet inspection infeasible. Examining the previous problematic factors, we realize that a protective measure must be implemented at the browser-level. Therefore, we propose a defensive measure, a browser plug-in called Fail-rebind, that can detect, inform, and protect users in the event of an attack. Afterwards, we discuss the merits and limitations of our method compared to prior methods. Our findings suggest that Fail-rebind does not nec essitate expert knowledge, works on different OSes and smart devices, and is independent of networks and location.
Related URL
http://scg.unibe.ch/archive/papers/Hazh21a.pdf
Handle
https://boris-portal.unibe.ch/handle/20.500.12422/201486
Show full item
File(s)
FileFile TypeFormatSizeLicensePublisher/Copright statementContent
Hazh21a.pdftextAdobe PDF270.88 KBAttribution-NonCommercial-NoDerivatives (CC BY-NC-ND 4.0)acceptedOpen
BORIS Portal
Bern Open Repository and Information System
Build: b407eb [23.05. 15:47]
Explore
  • Projects
  • Funding
  • Publications
  • Research Data
  • Organizations
  • Researchers
More
  • About BORIS Portal
  • Send Feedback
  • Cookie settings
  • Service Policy
Follow us on
  • Mastodon
  • YouTube
  • LinkedIn
UniBe logo