Collected research
Transaction Generators: Root Kits for Web
Jackson, Boneh and Mitchell define the Transaction Generator: malware that steals no credentials but waits inside the browser for the user to authenticate, then issues transactions on the live session. Stronger authentication and behavioural analytics are useless against it, so defence must move to transaction integrity and confirmation, which CardSpace and OpenID must also address.
Record
- Researcher
- Collin Jackson, Dan Boneh and John Mitchell
- Published by
- usenix.org
- Topic
- Other
In the archive
Related sources
- jackson Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Collin Jackson, Dan Boneh and John Mitchell, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .