隐私模式浏览器的安全性分析
Security Analysis of Private Mode Browsers
-
摘要: 浏览器插件与扩展能够破坏浏览器隐私模式的安全, 增加隐私浏览的复杂性。根据浏览器安全模型机制, 分析了公用模式与隐私模式数据状态集的有效性、持续性, 公用模式与隐私模式转换过程数据的持续性, 也分析了浏览器隐私模式CPH和SSL客户端密钥对隐私浏览存在的风险, 提出了改进隐私浏览模式的策略, 以预防浏览器扩展泄漏用户隐私活动信息给入侵者, 保证浏览器扩展与插件的安全性。Abstract: Browser plug-ins and extensions increase the complexity of private browsing, and can destroy completely the security of the browser privacy mode. Based on the browser security model mechanism the paper analyzes the validity and sustainability of the public and privacy mode data state sets, public and privacy mode conversion process data continuity, also analyzes CPH and SSL client key violation of the browser privacy mode. Finally, an improved private browsing mode strategy is proposed to prevent unintentional leakage of user privacy extended event information to the intruder, and to keep the security of browser extensions and plug-ins.