【24h】

Optical Delusions: A Study of Malicious QR Codes in the Wild

机译:视错觉:野外恶意QR码研究

获取原文
获取原文并翻译 | 示例

摘要

QR codes, a form of 2D barcode, allow easy interaction between mobile devices and websites or printed material by removing the burden of manually typing a URL or contact information. QR codes are increasingly popular and are likely to be adopted by malware authors and cyber-criminals as well. In fact, while a link can "look" suspicious, malicious and benign QR codes cannot be distinguished by simply looking at them. However, despite public discussions about increasing use of QR codes for malicious purposes, the prevalence of malicious QR codes and the kinds of threats they pose are still unclear. In this paper, we examine attacks on the Internet that rely on QR codes. Using a crawler, we performed a large-scale experiment by analyzing QR codes across 14 million unique web pages over a ten-month period. Our results show that QR code technology is already used by attackers, for example to distribute malware or to lead users to phishing sites. However, the relatively few malicious QR codes we found in our experiments suggest that, on a global scale, the frequency of these attacks is not alarmingly high and users are rarely exposed to the threats distributed via QR codes while surfing the web.
机译:QR码是2D条形码的一种形式,它消除了手动键入URL或联系信息的负担,从而使移动设备与网站或印刷材料之间的交互变得容易。 QR码越来越受欢迎,并且可能会被恶意软件作者和网络犯罪分子所采用。实际上,尽管链接可以“查看”可疑,但仅通过查看它们就无法区分恶意和良性QR码。但是,尽管公开讨论了越来越多地将QR码用于恶意目的,但恶意QR码的普遍性以及它们构成的威胁种类仍不清楚。在本文中,我们研究了依赖QR码的Internet攻击。通过使用搜寻器,我们在10个月的时间内分析了1400万个唯一网页上的QR码,从而进行了大规模的实验。我们的结果表明,攻击者已经使用了QR码技术,例如,分发恶意软件或将用户引导到钓鱼网站。但是,在我们的实验中发现的恶意QR码相对较少,这表明,在全球范围内,这些攻击的频率并没有令人震惊地高,并且用户在浏览网络时很少暴露于通过QR码分布的威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号