PhishGuard: A Browser Plug-in for Protection from Phishing
被引:0
|
作者:
Joshi, Yogesh
论文数: 0引用数: 0
h-index: 0
机构:
IIIT Bangalore, Elect City, Bangalore, Karnataka, IndiaIIIT Bangalore, Elect City, Bangalore, Karnataka, India
Joshi, Yogesh
[1
]
Saklikar, Samir
论文数: 0引用数: 0
h-index: 0
机构:
Motorola India Ltd, Bangalore, Karnataka, IndiaIIIT Bangalore, Elect City, Bangalore, Karnataka, India
Saklikar, Samir
[2
]
Das, Debabrata
论文数: 0引用数: 0
h-index: 0
机构:
IIIT Bangalore, Elect City, Bangalore, Karnataka, IndiaIIIT Bangalore, Elect City, Bangalore, Karnataka, India
Das, Debabrata
[1
]
Saha, Subir
论文数: 0引用数: 0
h-index: 0
机构:
Motorola India Ltd, Bangalore, Karnataka, IndiaIIIT Bangalore, Elect City, Bangalore, Karnataka, India
Saha, Subir
[2
]
机构:
[1] IIIT Bangalore, Elect City, Bangalore, Karnataka, India
[2] Motorola India Ltd, Bangalore, Karnataka, India
来源:
2008 2ND INTERNATIONAL CONFERENCE ON INTERNET MULTIMEDIA SERVICES ARCHITECTURE AND APPLICATION (IMSAA)
|
2008年
关键词:
Phishing;
Security;
Internet Theft;
Browser Plug-in;
HTTP;
D O I:
暂无
中图分类号:
TP3 [计算技术、计算机技术];
学科分类号:
0812 ;
摘要:
Phishing is an act of identity theft aimed at acquiring sensitive information such as usernames, passwords, credit card detail etc., by masquerading as a trustworthy entity in an electronic communication. Phishers use a number of different social engineering mechanism such as spoofed e-mail to fly to trick their victims. Data suggests that some of the phishing attacks have convinced up to 5% of their recipients to provide sensitive information to spoofed websites resulting in a direct loss of multi Billion Dollars across the countries. Though there are many existing anti-phishing solutions, Phishers continue to succeed to lure victims. In this paper, we have proposed a novel algorithm which aims at identifying a forged website by submitting random credentials before the actual credentials in a login process of a website. We have also proposed a mechanism for analysing the responses from tire server against lite submissions of all those credentials to determine if the website is original or phished one Though our idea is generic and would work in any authentication technologies which are based on exchange of any credentials, our current prototype is developed for sites supporting HTTP Digest Authentication and accepting userid and password pair as credential. Our algorithm is developed within a browser plug-in for Mozilla FireFox v3.0. and can detect phishing attack conclusively.