【24h】

Minimizing SSO Effort in Verifying SSL Anti-phishing Indicators

机译:最小化SSO在验证SSL反网络钓鱼指示符方面的努力

获取原文
获取原文并翻译 | 示例

摘要

In an on-line transaction, a user sends her personal sensitive data (e.g., password) to a server for authentication. This process is known as Single Sign-On (SSO). Subject to phishing and pharming attacks, the sensitive data may be disclosed to an adversary when the user is allured to visit a bogus server. There has been much research in anti-phishing methods and most of them are based on enhancing the security of browser indicator. In this paper, we present a completely different approach of defeating phishing and pharming attacks. Our method is based on encrypted cookie. It tags the sensitive data with the server's public key and stores it as a cookie on the user's machine. When the user visits the server so as to perform an online transaction, the sensitive data in the cookie will be encrypted with the stored public key of the server. The ciphertext can only be decrypted by the genuine server. Our encrypted cookie scheme (ECS) has the advantage that the user can ignore SSL indicator in the transaction process. The security is guaranteed even if the user accepts a malicious self-signed certificate. This advantage greatly releases user's burden of checking SSL indicator, which could be very difficult even for an experienced user when the phishing attacks have sophisticated vision design.
机译:在在线交易中,用户将其个人敏感数据(例如,密码)发送到服务器以进行认证。此过程称为单点登录(SSO)。遭受网络钓鱼和域名欺诈攻击时,当诱使用户访问伪造的服务器时,敏感数据可能会泄露给对手。关于反网络钓鱼的方法已有很多研究,并且大多数基于增强浏览器指示器的安全性。在本文中,我们提出了一种完全不同的方法来克服网络钓鱼和欺骗攻击。我们的方法基于加密的cookie。它使用服务器的公共密钥标记敏感数据,并将其作为cookie存储在用户的计算机上。当用户访问服务器以进行在线交易时,cookie中的敏感数据将使用服务器存储的公共密钥进行加密。密文只能由正版服务器解密。我们的加密cookie方案(ECS)的优势在于,用户可以在交易过程中忽略SSL指示符。即使用户接受恶意的自签名证书,也可以保证安全性。此优势极大地减轻了用户检查SSL指示器的负担,即使对于网络钓鱼攻击具有复杂的视觉设计的有经验的用户而言,这也可能非常困难。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号