Главная
Study mode:
on
1
Introduction
2
Agenda
3
Define the problem
4
Deployment Model
5
Inline Deployment Model
6
Attacker Goal
7
Browser Control
8
Network Control
9
Fundamental Issues
10
Sensor
11
Browser Fingerprint
12
Browser Audio
13
Normal Browser Data
14
Browser Fingerprints
15
Device accelerometer
16
Antitamper
17
payload
18
no guarantees
19
headless browsers
20
stripping attack
21
inline device
22
replay attacks
23
dynamic fingerprint
24
dynamic random token
25
Browser fingerprinting
26
Fake browser fingerprints
27
Canvas fingerprinting
28
Safari source code
29
Anti detect
30
User behavior
31
Authentication flows
32
Finger Print
Description:
Explore the vulnerabilities in fraud and bot detection solutions in this 52-minute conference talk from APPSEC Cali 2018. Delve into browser fingerprinting and user behavior tracking techniques, understanding their implementation as JavaScript snippets in user browsers. Discover why these signals are unreliable and learn about potential attacks against defenses that rely on them. Witness demonstrations of proof-of-concept attacks as presented by Mayank Dhiman, Principal Security Researcher at Stealth Security. Gain insights into online fraud and internet abuse mitigation, with a focus on detecting and countering malicious automation attacks. Cover topics such as deployment models, attacker goals, fundamental issues in sensor data, browser fingerprinting techniques, and user behavior analysis. Understand the limitations of current anti-fraud measures and explore strategies to enhance security in web applications.

Breaking Fraud and Bot Detection Solutions

OWASP Foundation
Add to list