Abstract
dc:descriptionThe Web is a ubiquitous tool for a wide range of stakeholders–all of whom rely on the ability to reliably locate remote resources. Uniform Resource Locators (URLs) guide the tens of trillions of HyperText Transfer Protocol (HTTP) requests in the Internet every day. If URLs are ambiguously understood, then the Web loses the ability to reliably locate resources. Attackers can take advantage of the ambiguity to misdirect both humans and their computers to untrustworthy resources. We show that for both humans and machines, URL complexity causes parsing inconsistencies that undermine security assumptions of HTTP. The processes users use to parse identity from URLs are insufficient to handle complex URLs – leaving Web users vulnerable to misdirection. We identify and categorize nine differences in URL parsing across more than a dozen URL parsers that enable us to engineer “equivocal URLs.” These equivocal URLs can cause false positives in malicious URL classifiers when the classifier’s URL parser is different from the URL parser of the client it is protecting. We measure added URL complexity stemming from the fact that both users and back-end systems share reliance on URLs. We evaluate the feasibility of reducing URL complexity by moving humans away from direct URL interaction.
Degree
thesis:*- Name thesis:degree_name
- Ph.D.
- Level thesis:degree_level
- Dissertation
- Discipline thesis:degree_discipline
- Computer Science
- Grantor
- University of Illinois at Urbana-Champaign
- Year dc:date
- 2022
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Reynolds, Joshua
- Contributors dc:contributor
-
- Bailey, Michael D
- Gunter, Carl
- Bates, Adam
- Seamons, Kent
Subjects
dc:subject × 6Rights
dc:rights- Statement dc:rights
-
- ©2022 Joshua Reynolds
- Language dc:language
- en, eng
Identifiers
dc:identifier.*- Handle dc:identifier
- https://hdl.handle.net/2142/117547