Computing Reviews
Today's Issue Hot Topics Search Browse Recommended My Account Log In
Review Help
Search
Detecting in-flight page changes with Web tripwires
Reis C., Gribble S., Kohno T., Weaver N.  Networked systems design and implementation (Detecting In-flight Page Changes with Web Tripwires on Networked Systems Design and Implementation, San Francisco, California, Apr 16-18, 2008)31-44.2008.Type:Proceedings
Date Reviewed: Nov 25 2008

This paper proposes a number of techniques for detecting unauthorized changes to Web pages on their way from the server to the client. Pop-ups and other forms of advertising inserted into the pages served by providers of free Web hosting services are perhaps the best illustration of this problem. Unfortunately, as the authors found in their study, this practice is much more widespread than that. More than just being a minor annoyance, these changes may also introduce vulnerabilities into otherwise secure and safe Web pages.

Reis et al. address this problem by inserting JavaScript code into Web pages. This code works as a tripwire, alerting the end user and the server about unauthorized modifications to the protected Web page. The few different approaches described in the paper differ by type of modifications that can be detected, but they all depend on a script executed inside the Web browser to compare the Web page being displayed with a known good digest or a second copy, fetched from the server by the script. Each proposed technique is then implemented and measured in terms of amount of network traffic, server throughput, and client latency. The benchmark results show that tripwires have negligible impact on server throughput, which is their major advantage over the computationally intensive hypertext transfer protocol over secure sockets layer (HTTPS) protocol. The authors discuss possible ways to circumvent the Web tripwires and how to defend against such attacks.

Given the importance of the Web, as a way to access applications and information, and communicate with people and organizations, this paper is a must-read for developers of content management systems (CMSs). I would like to see the proposed techniques developed into plug-ins for some of the popular CMS frameworks, to make them easily accessible for the less technically oriented Web publishers.

Reviewer:  Maciej Golebiewski Review #: CR136275 (1002-0198)
Bookmark and Share
 
Document Analysis (I.7.5 ... )
 
 
Client/ Server (C.2.4 ... )
 
 
Pattern Analysis (I.5.2 ... )
 
 
World Wide Web (WWW) (H.3.4 ... )
 
 
Distributed Systems (C.2.4 )
 
Would you recommend this review?
yes
no
Other reviews under "Document Analysis": Date
Generating indicative-informative summaries with sumUM: a 3D dynamic virtual shop
Saggion H., Lapalme G. Computational Linguistics 28(4): 497-526, 2002. Type: Article
Jun 20 2003
Parameter-Free Geometric Document Layout Analysis
Lee S., Ryu D. IEEE Transactions on Pattern Analysis and Machine Intelligence 23(11): 1240-1256, 2001. Type: Article
Jul 26 2002
A hierarchical neural network document classifier with linguistic feature selection
Chen C., Lee H., Hwang C. Applied Intelligence 23(3): 277-294, 2005. Type: Article
Aug 2 2006
more...

E-Mail This Printer-Friendly
Send Your Comments
Contact Us
Reproduction in whole or in part without permission is prohibited.   Copyright 1999-2024 ThinkLoud®
Terms of Use
| Privacy Policy