iBet uBet web content aggregator. Adding the entire web to your favor.
iBet uBet web content aggregator. Adding the entire web to your favor.



Link to original content: https://unpaywall.org/10.5220/0012731300003767
SciTePress - Publication Details
loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Authors: José Areia 1 ; 2 ; Bruno Santos 1 ; 2 and Mário Antunes 1 ; 3

Affiliations: 1 School of Management and Technology (ESTG), Polytechnic of Leiria, Leiria, Portugal ; 2 Computer Science and Communication Research Centre (CIIC), Polytechnic of Leiria, Leiria, Portugal ; 3 INESC TEC, Center for Research in Advanced Computing Systems, Porto, Portugal

Keyword(s): Web Security, Browser Password Managers, Malware Development, Network Security, Security Analysis.

Abstract: Memorising passwords poses a significant challenge for individuals, leading to the increasing adoption of password managers, particularly browser password managers. Despite their benefits to users’ daily routines, the use of these tools introduces new vulnerabilities to web and network security. This paper aims to investigate these vulnerabilities and analyse the security mechanisms of browser-based password managers integrated into Google Chrome, Microsoft Edge, Opera GX, Mozilla Firefox, and Brave. Through malware development and deployment, Dvorak is capable of extracting essential files from the browser’s password manager for subsequent decryption. To assess Dvorak functionalities we conducted a controlled security analysis across all aforementioned browsers. Our findings reveal that the designed malware successfully retrieves all stored passwords from the tested browsers when no master password is used. However, the results differ depending on whether a master password is used. A comparison between browsers is made, based on the results of the malware. The paper ends with recommendations for potential strategies to mitigate these security concerns. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 173.236.136.203

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Areia, J. ; Santos, B. and Antunes, M. (2024). Dvorak: A Browser Credential Dumping Malware. In Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT; ISBN 978-989-758-709-2; ISSN 2184-7711, SciTePress, pages 434-441. DOI: 10.5220/0012731300003767

@conference{secrypt24,
author={José Areia and Bruno Santos and Mário Antunes},
title={Dvorak: A Browser Credential Dumping Malware},
booktitle={Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT},
year={2024},
pages={434-441},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012731300003767},
isbn={978-989-758-709-2},
issn={2184-7711},
}

TY - CONF

JO - Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT
TI - Dvorak: A Browser Credential Dumping Malware
SN - 978-989-758-709-2
IS - 2184-7711
AU - Areia, J.
AU - Santos, B.
AU - Antunes, M.
PY - 2024
SP - 434
EP - 441
DO - 10.5220/0012731300003767
PB - SciTePress