...
首页> 外文期刊>Information management & computer security >Examining the effectiveness of phishing filters against DNS based phishing attacks
【24h】

Examining the effectiveness of phishing filters against DNS based phishing attacks

机译:检查网络钓鱼过滤器针对基于DNS的网络钓鱼攻击的有效性

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - This paper aims to report on research that tests the effectiveness of anti-phishing tools in detecting phishing attacks by conducting some real-time experiments using freshly hosted phishing sites. Almost all modern-day Web browsers and antivirus programs provide security indicators to mitigate the widespread problem of phishing on the Internet. Design/methodology/approach - The current work examines and evaluates the effectiveness of five popular Web browsers, two third-party phishing toolbar add-ons and seven popular antivirus programs in terms of their capability to detect locally hosted spoofed websites. The same tools have also been tested against fresh phishing sites hosted on Internet. Findings - The experiments yielded alarming results. Although the success rate against live phishing sites was encouraging, only 3 of the 14 tools tested could successfully detect a single spoofed website hosted locally. Originality/value - This work proposes the inclusion of domain name system server authentication and verification of name servers for a visiting website for all future anti-phishing toolbars. It also proposes that a Web browser should maintain a white list of websites that engage in online monetary transactions so that when a user requires to access any of these, the default protocol should always be HTTPS (Hypertext Transfer Protocol Secure), without which a Web browser should prevent the page from loading.
机译:目的-本文旨在通过使用新鲜托管的网络钓鱼站点进行一些实时实验来报告有关测试反网络钓鱼工具在检测网络钓鱼攻击中的有效性的研究报告。几乎所有当今的Web浏览器和防病毒程序都提供了安全指标,以减轻Internet上网络钓鱼的广泛问题。设计/方法/方法-当前的工作检查和评估了五个流行的Web浏览器,两个第三方网页仿冒工具栏加载项以及七个流行的防病毒程序在检测本地托管的欺骗性网站方面的有效性。相同的工具也已经针对Internet上托管的最新网络钓鱼站点进行了测试。发现-实验产生了令人震惊的结果。尽管针对实时网络钓鱼站点的成功率令人鼓舞,但在测试的14种工具中,只有3种可以成功检测到本地托管的单个欺骗性网站。原创性/价值-这项工作建议将域名系统服务器身份验证和访问网站的名称服务器验证纳入所有将来的反网络钓鱼工具栏中。它还建议Web浏览器应维护参与在线货币交易的网站白名单,以便当用户需要访问其中任何一项时,默认协议应始终为HTTPS(安全超文本传输​​协议),否则,Web浏览器应阻止该页面加载。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号