Clickjacking Revisited: A Perceptual View of UI Security

No ratings

Presented at BlackHatUSA 2013 by

We revisit UI security attacks (such as clickjacking) from a perceptual perspective and identify novel attacks. Our perceptual view on UI security attacks helps identify new attacks on UI security. We develop five attacks that bypass current defenses. Our attacks are powerful with a 100% success rate in some cases. However, they only scratch the surface of possible perceptual attacks on UI integrity, and we posit that a number of attacks are possible with a comprehensive study of human perception. Finally, we argue that, due to the complex nature of human perception, defending against such attacks is challenging and requires further research taking user perception and new computer vision techniques into account.