Proceedings 2020 Workshop on Measurements, Attacks, and Defenses for the Web 2020
DOI: 10.14722/madweb.2020.23008
|View full text |Cite
|
Sign up to set email alerts
|

Shepherd: a Generic Approach to Automating Website Login

Abstract: To gauge adoption of web security measures, largescale testing of website security is needed. However, the diversity of modern websites makes a structured approach to testing a daunting task. This is especially a problem with respect to logging in: there are many subtle deviations in the flow of the login process between websites. Current efforts investigating login security typically are semi-automated, requiring manual intervention which does not scale well. Hence, comprehensive studies of post-login areas h… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

1
12
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
2
2
1

Relationship

1
4

Authors

Journals

citations
Cited by 12 publications
(13 citation statements)
references
References 12 publications
1
12
0
Order By: Relevance
“…For example, sites where registration is simple and accounts are not associated with (personal) value will be prevalent, while other accounts (banks, social media, online stores), will be underrepresented or even absent due to the rules governing the crowdsourcing effort. The current largest study based on this approach [4] gathered credentials for ∼50K sites, and was successful on 7.1K of these (14%).…”
Section: Crowd-sourcing Credentialsmentioning
confidence: 99%
See 4 more Smart Citations
“…For example, sites where registration is simple and accounts are not associated with (personal) value will be prevalent, while other accounts (banks, social media, online stores), will be underrepresented or even absent due to the rules governing the crowdsourcing effort. The current largest study based on this approach [4] gathered credentials for ∼50K sites, and was successful on 7.1K of these (14%).…”
Section: Crowd-sourcing Credentialsmentioning
confidence: 99%
“…To collect data, we use Shepherd [4], a crawling framework based on Selenium and WebDriver to automate interaction with the Chromium browser. It uses a multi-step approach to automate the login process for unknown sites.…”
Section: Data Collection Toolmentioning
confidence: 99%
See 3 more Smart Citations