Today, web injection manifests in many forms, but fundamentally occurs when malicious and unwanted actors tamper directly with browser sessions for their own profit. In this work we illuminate the scope and negative impact of one of these forms, ad injection, in which users have ads imposed on them in addition to, or different from, those that websites originally sent them. We develop a multi-staged pipeline that identifies ad injection in the wild and captures its distribution and revenue chains. We find that ad injection has entrenched itself as a cross-browser monetization platform impacting more than 5% of unique daily IP addresses accessing Googletens of millions of users around the globe. Injected ads arrive on a clients machine through multiple vectors: our measurements identify 50,870 Chrome extensions and 34,407 Windows binaries, 38% and 17% of which are explicitly malicious. A small number of software developers support the vast majority of these injectors who in turn syndicate from the larger ad ecosystem. We have contacted the Chrome Web Store and the advertisers targeted by ad injectors to alert each of the deceptive practices involved.
Ad injection at scale: assessing deceptive advertisement modifications
| Available Media | |
|---|---|
| Conference | Security and Privacy (S&P) - 2015 |
| Authors | Kurt Thomas , Elie Bursztein , Chris Grier , |
| Award | Distinguished Practical Paper Award |
| Citation | BibTeX |
Related
anti-abuse
Picasso: Lightweight Device Class Fingerprinting for Web Clients
publications
SPSM 2016
anti-abuse
Secrets, lies, and account recovery: lessons from the use of personal knowledge questions at google
publications
WWW 2015
anti-abuse
Handcrafted fraud and extortion: manual account hijacking in the wild
publications
IMC 2014