首页> 外文期刊>Information Security Technical Report >Secure authentication scheme to thwart RT MITM, CR MITM and malicious browser extension based phishing attacks
【24h】

Secure authentication scheme to thwart RT MITM, CR MITM and malicious browser extension based phishing attacks

机译:安全身份验证方案可阻止RT MITM,CR MITM和基于恶意浏览器扩展的网络钓鱼攻击

获取原文
获取原文并翻译 | 示例
       

摘要

Securing user credentials against phishing attacks is an important and challenging research problem. These days phishing is carried out by real time (RT) and control relay (CR) man in the middle (MITM) attacks or by malicious browser extensions. Existing user authentication schemes are either incapable of handling these attacks or they are complex to learn and use or they require users to purchase and carry additional hardware such as a security key. In this paper, we propose a new secure authentication scheme for anti-phishing, which uses the Bluetooth address of the user's smartphone for user identification along with App instance ids and a user password for authentication. The analysis of the results of our experiments shows that the proposed scheme is safe against RT MITM and CR MITM phishing attacks and the attacks launched via malicious browser extensions. It is also efficient in terms of memory and CPU utilization. The comparison of the proposed scheme with the existing schemes in terms of usability and deployability shows that it is better than the schemes that can provide the same level of security.
机译:保护用户凭据免受网络钓鱼攻击是一个重要且具有挑战性的研究问题。如今,网络钓鱼是通过实时(RT)和控制中继(CR)中间人(MITM)攻击或恶意浏览器扩展来进行的。现有的用户身份验证方案要么无法处理这些攻击,要么学习和使用起来很复杂,要么要求用户购买并携带其他硬件(例如安全密钥)。在本文中,我们提出了一种新的防网络钓鱼安全身份验证方案,该方案使用用户智能手机的蓝牙地址进行用户身份识别,并使用App实例ID和用户密码进行身份验证。对我们的实验结果进行的分析表明,该方案可以安全地抵抗RT MITM和CR MITM网络钓鱼攻击以及通过恶意浏览器扩展程序发起的攻击。就内存和CPU利用率而言,它也是有效的。从可用性和可部署性方面比较所建议的方案和现有方案表明,它比可以提供相同级别安全性的方案更好。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号