Abstract

Man-in-the-Middle (MitM), one of the best known attacks in the world of computer security, is among the greatest concerns for professionals in the field. Main goal of MitM is to compromise confidentiality, integrity and availability of data flowing between source and destination. However, most of its many variants involve difficulties that make it not always possible. The present paper aims at modelling and describing a new method of attack, named Browser-in-the-Middle (BitM) which, despite the similarities with MitM in the way it controls the data flow between a client and the service it accesses, bypasses some of MitM’s typical shortcomings. It could be started by phishing techniques and in some cases coupled to the well-known Man-in-the-Browser (MitB) attack. It will be seen how BitM expands the range of the possible attacker’s actions, at the same time making them easier to implement. Among its features, the absence of the need to install malware of any kind on the victim’s machine and the total control it allows the attacker are to be emphasized.

Details

Title
Browser-in-the-Middle (BitM) attack
Author
Tommasi, Franco 1   VIAFID ORCID Logo  ; Catalano, Christian 1   VIAFID ORCID Logo  ; Taurino Ivan 1 

 University of Salento, Dipartimento di Ingegneria dell’Innovazione, Lecce, Italy (GRID:grid.9906.6) (ISNI:0000 0001 2289 7785) 
Pages
179-189
Publication year
2022
Publication date
Apr 2022
Publisher
Springer Nature B.V.
ISSN
16155262
e-ISSN
16155270
Source type
Scholarly Journal
Language of publication
English
ProQuest document ID
2641239361
Copyright
© The Author(s) 2021. This work is published under http://creativecommons.org/licenses/by/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.