• DocumentCode
    2967012
  • Title

    Cross-domain vulnerabilities over social networks

  • Author

    Bernard, Christian ; Debar, Herve ; Benayoune, Salim

  • Author_Institution
    ESIGETEL, Villejuif, France
  • fYear
    2012
  • fDate
    21-23 Nov. 2012
  • Firstpage
    8
  • Lastpage
    13
  • Abstract
    Recent years have seen a tremendous growth of social networks such as Facebook and Twitter. At the same time, the share of video traffic in the Internet has also significantly increased, and the two functions are getting closer to one another. YouTube, the most famous video sharing site, allows people to comment on videos with other people while Facebook and Twitter are important vectors into sharing videos. Both video channels and social networks are increasingly vulnerable attack targets. For example, social networks are also considerable spam and phishing vectors, and Adobe Flash as the premier video streaming application is associated with numerous software vulnerabilities. This is a good way for attackers to compromise sites with embedded Flash objects. In this paper, we present the technical background of the cross-domain mechanisms and the security implications. Several recent studies have demonstrated the weakness of the cross-domain policy, leading to session hijacking or the leakage of sensitive information. Current solutions to detect these vulnerabilities use a client-side approach. The purpose of our work is to present a new approach based on network flows analysis to detect malicious behavior.
  • Keywords
    Internet; computer crime; social networking (online); unsolicited e-mail; video signal processing; video streaming; Adobe Flash; Facebook; Internet; Twitter; YouTube; cross-domain vulnerabilities; phishing vectors; social networks; spam; video sharing site; video streaming application; video traffic; Browsers; Internet; Security; Servers; Streaming media; YouTube; Cross-domain attack; Flash security; Social Network security; YouTube;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Aspects of Social Networks (CASoN), 2012 Fourth International Conference on
  • Conference_Location
    Sao Carlos
  • Print_ISBN
    978-1-4673-4793-8
  • Type

    conf

  • DOI
    10.1109/CASoN.2012.6412370
  • Filename
    6412370