How do they find us? A study of geolocation tracking techniques of malicious web sites

Geolocation cloaking is a process in which varying and customised web content is delivered to visiting users based on the geographical information derived from the users’ system and network variables. Geolocation cloaking allows a malicious web site to: 1) Increase the success rate of an attacks by...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Computers & security 2020-10, Vol.97, p.101948-14, Article 101948
Hauptverfasser: Mansoori, Masood, Welch, Ian
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Geolocation cloaking is a process in which varying and customised web content is delivered to visiting users based on the geographical information derived from the users’ system and network variables. Geolocation cloaking allows a malicious web site to: 1) Increase the success rate of an attacks by targeting a specific population using sociocultural attributes of the visiting user and, perform targeted social engineering attacks. 2) Deliver benign content to requesting users (or detection systems) who do not reside in the geographical location specified by the attacker and, subsequently limit exposure and bypass detection entirely regardless of the detection engine utilised. In this paper we provide an overview of the range of geolocation detection techniques which could potentially be used to estimate the location of a visiting user and perform geolocation cloaking attacks. We discuss these systems in terms of their operation and feasibility to be utilised by a malicious web site.
ISSN:0167-4048
1872-6208
DOI:10.1016/j.cose.2020.101948