The Experts below are selected from a list of 8895 Experts worldwide ranked by ideXlab platform

Roya Ensafi - One of the best experts on this subject based on the ideXlab platform.

  • the Chain of implicit trust an analysis of the web third party resources loading
    The Web Conference, 2019
    Co-Authors: Muhammad Ikram, Rahat Masood, Gareth Tyson, Mohamed Ali Kaafar, Noha Loizon, Roya Ensafi
    Abstract:

    The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a Dependency Chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The Chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of Dependency Chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short Dependency Chains (below 3 levels), we find websites with Dependency Chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem.

  • the Chain of implicit trust an analysis of the web third party resources loading
    arXiv: Cryptography and Security, 2019
    Co-Authors: Muhammad Ikram, Rahat Masood, Gareth Tyson, Mohamed Ali Kaafar, Noha Loizon, Roya Ensafi
    Abstract:

    The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. However, the latter can further load resources hosted on other domains. For each website, this creates a Dependency Chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The Chain can only be loosely controlled as first-party websites often have little, if any, visibility of where these resources are loaded from. This paper performs a large-scale study of Dependency Chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short Dependency Chains (below 3 levels), we find websites with Dependency Chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious --- although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem. By running sandboxed experiments, we observe a range of activities with the majority of suspicious JavaScript downloading malware; worryingly, we find this propensity is greater among implicitly trusted JavaScripts.

Muhammad Ikram - One of the best experts on this subject based on the ideXlab platform.

  • the Chain of implicit trust an analysis of the web third party resources loading
    The Web Conference, 2019
    Co-Authors: Muhammad Ikram, Rahat Masood, Gareth Tyson, Mohamed Ali Kaafar, Noha Loizon, Roya Ensafi
    Abstract:

    The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a Dependency Chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The Chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of Dependency Chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short Dependency Chains (below 3 levels), we find websites with Dependency Chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem.

  • the Chain of implicit trust an analysis of the web third party resources loading
    arXiv: Cryptography and Security, 2019
    Co-Authors: Muhammad Ikram, Rahat Masood, Gareth Tyson, Mohamed Ali Kaafar, Noha Loizon, Roya Ensafi
    Abstract:

    The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. However, the latter can further load resources hosted on other domains. For each website, this creates a Dependency Chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The Chain can only be loosely controlled as first-party websites often have little, if any, visibility of where these resources are loaded from. This paper performs a large-scale study of Dependency Chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short Dependency Chains (below 3 levels), we find websites with Dependency Chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious --- although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem. By running sandboxed experiments, we observe a range of activities with the majority of suspicious JavaScript downloading malware; worryingly, we find this propensity is greater among implicitly trusted JavaScripts.

Ensafi R - One of the best experts on this subject based on the ideXlab platform.

  • Measuring and Analysing the Chain of Implicit Trust: AStudy of Third-party Resources Loading
    'Association for Computing Machinery (ACM)', 2020
    Co-Authors: Ikram M, Masood R, Tyson G, Kafaar M, Loizon N, Ensafi R
    Abstract:

    The web is a tangled mass of interconnected services, whereby websites import a range of external resources from various third-party domains. The latter can also load further resources hosted on other domains. For each website, this creates a Dependency Chain underpinned by a form of implicit trust between the first-party and transitively connected third parties. The Chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This article performs a large-scale study of Dependency Chains in the web to find that around 50% of first-party websites render content that they do not directly load. Although the majority (84.91%) of websites have short Dependency Chains (below three levels), we find websites with Dependency Chains exceeding 30. Using VirusTotal, we show that 1.2% of these third parties are classified as suspicious—although seemingly small, this limited set of suspicious third parties have remarkable reach into the wider ecosystem. We find that 73% of websites under-study load resources from suspicious third parties, and 24.8% of first-party webpages contain at least three third parties classified as suspicious in their Dependency Chain. By running sandboxed experiments, we observe a range of activities with the majority of suspicious JavaScript codes downloading malware

Mohamed Ali Kaafar - One of the best experts on this subject based on the ideXlab platform.

  • the Chain of implicit trust an analysis of the web third party resources loading
    The Web Conference, 2019
    Co-Authors: Muhammad Ikram, Rahat Masood, Gareth Tyson, Mohamed Ali Kaafar, Noha Loizon, Roya Ensafi
    Abstract:

    The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a Dependency Chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The Chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of Dependency Chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short Dependency Chains (below 3 levels), we find websites with Dependency Chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem.

  • the Chain of implicit trust an analysis of the web third party resources loading
    arXiv: Cryptography and Security, 2019
    Co-Authors: Muhammad Ikram, Rahat Masood, Gareth Tyson, Mohamed Ali Kaafar, Noha Loizon, Roya Ensafi
    Abstract:

    The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. However, the latter can further load resources hosted on other domains. For each website, this creates a Dependency Chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The Chain can only be loosely controlled as first-party websites often have little, if any, visibility of where these resources are loaded from. This paper performs a large-scale study of Dependency Chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short Dependency Chains (below 3 levels), we find websites with Dependency Chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious --- although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem. By running sandboxed experiments, we observe a range of activities with the majority of suspicious JavaScript downloading malware; worryingly, we find this propensity is greater among implicitly trusted JavaScripts.

Rahat Masood - One of the best experts on this subject based on the ideXlab platform.

  • the Chain of implicit trust an analysis of the web third party resources loading
    The Web Conference, 2019
    Co-Authors: Muhammad Ikram, Rahat Masood, Gareth Tyson, Mohamed Ali Kaafar, Noha Loizon, Roya Ensafi
    Abstract:

    The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a Dependency Chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The Chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of Dependency Chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short Dependency Chains (below 3 levels), we find websites with Dependency Chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem.

  • the Chain of implicit trust an analysis of the web third party resources loading
    arXiv: Cryptography and Security, 2019
    Co-Authors: Muhammad Ikram, Rahat Masood, Gareth Tyson, Mohamed Ali Kaafar, Noha Loizon, Roya Ensafi
    Abstract:

    The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. However, the latter can further load resources hosted on other domains. For each website, this creates a Dependency Chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The Chain can only be loosely controlled as first-party websites often have little, if any, visibility of where these resources are loaded from. This paper performs a large-scale study of Dependency Chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short Dependency Chains (below 3 levels), we find websites with Dependency Chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious --- although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem. By running sandboxed experiments, we observe a range of activities with the majority of suspicious JavaScript downloading malware; worryingly, we find this propensity is greater among implicitly trusted JavaScripts.