Protecting (even) Naïve Web Users, or: Preventing Spoofing and Establishing Credentials of Web Sites

نویسنده

  • Amir Herzberg
چکیده

In spite of the use of standard web security measures, swindlers often clone sensitive web sites and/or present false credentials, causing substantial damages to individuals and corporations. Several papers presented such web spoofing attacks, and suggested countermeasures, mostly by improved browser user interface. However, we argue that these countermeasures are inappropriate to most non-expert web users; indeed, they are irrelevant to most practical web-spoofing attacks, which focus on non-expert users. In fact, even expert users could be victim of these practical, simple spoofing attacks, resulting in identity theft or other fraud. We present the trusted credentials area, a simple and practical browser UI enhancement, which allows secure identification of sites and validation of their credentials, thereby preventing web-spoofing, even for naïve users. The trusted credentials area is a fixed part of the browser window, which displays only authenticated credentials, and in particular logos, icons and seals. In fact, we recommend that web sites always provide credentials (e.g. logo) securely, and present them in the trusted credentials area; this will help users to notice the absence of secure logo in spoofed sites. Existing web security mechanisms (SSL/TLS) may cause substantial overhead if applied to most web pages, as required for securing credentials (e.g. logo) of each page. We present a simple alternative mechanism to secure web pages and credentials, with acceptable overhead. Finally, we suggest additional anti-spoofing measures for site owners and web users, mainly until deployment of the trusted credentials area.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Preventing Web-Spoofing with Automatic Detecting Security Indicator

The anti-spoofing community has been intensively proposing new methods for defending against new spoofing techniques. It is still challenging for protecting näıve users from advanced spoofing attacks. In this paper, we analyze the problems within those anti-spoofing mechanisms and propose a new Automatic Detecting Security Indicator (ADSI) scheme. This paper describe the trust model in ADSI in ...

متن کامل

Stopping a Phishing Attack, Even when the Victims Ignore Warnings

Several factors make phishing a very challenging security problem. First, the victim unknowingly assists the attacker, by typing her credentials into a spoofed web site. Second, it is hard to identify web sites as suspicious using a fixed algorithm: phishers adapt quickly, and it is difficult to anticipate the ingenuity of all future attackers with a fixed set of rules. Third, users tend to ign...

متن کامل

Privatizing user credential information of Web services in a shared user environment

-User credentials security is one of the most important tasks in Web World. Most Web sites on the Internet that support user accounts store the users' credentials in a database. Now a days, most of the web browsers offer auto login feature for the favourite web sites such as yahoo, google, gmail etc. using these credential information. This facilitates the misuse of user credentials. Privatizin...

متن کامل

Protecting web users from phishing , spoofing and malware

We describe the current state of web security, and identify the main problems. We then present proposals for improvements, including: secure site identification widget; secure and convenient`single click logon`; improved validation certificates; and using public-key signatures and automated resolutions and penalties, to defend against malicious content including malware. The web and its users a...

متن کامل

SSL-enabled trusted communication: Spoofing and protecting the non-cautious users

The anti-spoofing community has been intensively proposing new methods for defending against new web-spoofing techniques. In this paper, we analyze the problems within current anti-spoofing mechanisms, and propose a new SSL protected trust model. Then, we describe the attacks on SSL protected trusted communication. In this paper, we also propose the new Automatic Detecting Security Indicator sc...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2004