首页> 外文会议>Internet Multimedia Services Architecture and Applications (IMSAA), 2009 >Mitigating man in the middle attack over secure sockets layer
【24h】

Mitigating man in the middle attack over secure sockets layer

机译:缓解中间人对安全套接字层的攻击

获取原文

摘要

Phishing is a social engineering mechanism to steal the user's credentials which are then used for identity theft leading to financial benefit. Currently majority of Phishing attacks are very unsophisticated as they focus on collecting just the credentials and do not try to validate in real time whether the received credentials are correct. It is obvious that next generation Phishing attacks will, in real time, try to check the credentials and also try to exploit the same. It is easy for a Phisher to behave as a man-in-the middle (MITM) between the user and the targeted site which is being phished. The problem with MITM attack is all the heuristics like monitoring domain name for special characters, using blacklists, page analysis etc , fail to restrict the Phisher. One of the significant literature available in this area i.e., PwdHash, which is successful for attacks when the user is on a URL other than genuine website. In this paper, we have proposed and implemented a novel approach to solve MITM over SSL which uses the genuine website URL. To tackle such attacks we propose hashing the user password with the public key of the server's digital certificate. This approach beats the MITM, since the MITM receives the hash of the original password which cannot be reused. We prove our concept with a browser plugin.
机译:网络钓鱼是一种社会工程学机制,用于窃取用户的凭据,然后将其用于身份盗用,从而带来经济利益。当前,大多数网络钓鱼攻击都非常复杂,因为它们只关注收集凭据,而不尝试实时验证接收到的凭据是否正确。显然,下一代网络钓鱼攻击将实时尝试检查凭据并尝试利用它们。网络钓鱼者很容易充当用户与被钓鱼目标站点之间的中间人(MITM)。 MITM攻击的问题是所有启发式方法,例如监视域名中的特殊字符,使用黑名单,页面分析等,均无法限制网络钓鱼者。这是该领域的重要文献之一,即PwdHash,当用户使用非真实网站的URL时,它可以成功地进行攻击。在本文中,我们提出并实现了一种使用真实网站URL的SSL上的MITM解决方案。为了解决此类攻击,我们建议使用服务器数字证书的公钥对用户密码进行哈希处理。这种方法优于MITM,因为MITM接收了无法重用的原始密码的哈希值。我们通过浏览器插件证明了我们的概念。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号