Affiliation:
1. Department of Computer Science & Engineering International Institute of Information Technology Naya Raipur India
Abstract
AbstractClickjacking is a fast‐growing threat for users online. Here, an attacker program shows a user‐interface (UI) which is entirely out of context, by concealing a very sensitive UI element and rendering it in such a way that it is not visible (transparent) to the end user. The user is then tricked into clicking on the hidden element. By exploiting cameras and publishing unwanted messages, these attacks have the potential to do significant harm. Many websites still lack server‐side minimum security (eg, X‐Frame‐Options header, Content‐Security‐Policy Header, etc) and are hence susceptible to clickjacking. Additionally, client‐side defense methods fare poorly and are ineffective against advanced clickjacking attack types. This paper focuses on dealing with the detection of a possibility of a website being clickjacked. It also predicts the Level of Security of a website against a clickjacking attack and the possible security countermeasures that could be taken to avoid a clickjacking attack on the website. Testing this approach on various websites has proved effective in detecting whether or not a website is vulnerable to clickjacking.
Reference9 articles.
1. A Solution for the Automated Detection of Clickjacking Attacks by Marco Balduzzi from Institute Eurecom Manuel Egele from Technical University Vienna Engin Kirda from Institute Eurecom Davide Balzarotti from Institute Eurecom and Christopher Kruegel from University of California.
2. On Detection and Prevention of Clickjacking Attack for OSNs