FakeX: A Framework for Detecting Fake Reviews of Browser Extensions
Paper i proceeding, 2024

Browser extensions boost user experience on the web. Similarly to smartphone app stores, browsers like Chrome distribute browser extensions via their Web Store, enabling a thriving market of third-party developed extensions. The Web Store incorporates a user review system to help users decide which extensions to install. Unfortunately, the open nature of the review system is subject to reputation manipulation. As browser vendors fight reputation manipulation, attackers employ more sophisticated methods to stay under the radar. Focusing on fake reviews, we identify several techniques attackers use: fake accounts, disjoint sets of fake accounts for different extensions, automation of generated reviews, and focusing on reviews rather than ratings. We present FakeX, a framework to detect fake reviews by focusing on inference from review metadata. FakeX employs five distinct methods, including temporal distribution analysis, relationship clustering, and ratio-based assessments, to unveil patterns indicative of fake reviews. Evaluation of over 1.7 million reviews reveals the effectiveness of FakeX in identifying hundreds of fake review campaigns. Furthermore, our investigation of these fake reviews uncovers 86 malicious extensions, mounting attacks that range from data-stealing to monetization, impacting over 64 million users. In addition, we collaborate with Adblock Plus and Avast to demonstrate FakeX in action, expanding a seed list of newly detected malicious extensions to discover a further 16 malicious extensions with millions of users, where, in some cases, attackers tried to improve malicious code.

Web Security

Fake Reviews

Browser Extensions

Författare

Eric Olsson

Chalmers, Data- och informationsteknik, Informationssäkerhet

Benjamin Eriksson

Student vid Chalmers

Pablo Picazo-Sanchez

Högskolan i Halmstad

Chalmers, Data- och informationsteknik, Informationssäkerhet

Lukas Andersson

Chalmers, Data- och informationsteknik, Informationssäkerhet

Andrei Sabelfeld

Chalmers, Data- och informationsteknik, Informationssäkerhet

ACM AsiaCCS 2024 - Proceedings of the 19th ACM Asia Conference on Computer and Communications Security

1127-1142
9798400704826 (ISBN)

19th ACM Asia Conference on Computer and Communications Security, AsiaCCS 2024
Singapore, Singapore,

Ämneskategorier

Datavetenskap (datalogi)

DOI

10.1145/3634737.3656999

Mer information

Senast uppdaterat

2024-07-30