首页> 外文OA文献 >Quick Response Code Secure: a cryptographically secure anti-phishing tool for QR code attacks.
【2h】

Quick Response Code Secure: a cryptographically secure anti-phishing tool for QR code attacks.

机译:快速响应代码安全:一种用于QR码攻击的加密安全反网络钓鱼工具。

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The two-dimensional quick response (QR) codes can be misleading due to the difficulty in differentiating a genuine QR code from a malicious one. Since, the vulnerability is practically part of their design, scanning a malicious QR code can direct the user to cloned malicious sites resulting in revealing sensitive information. In order, to evaluate the vulnerabilities and propose subsequent countermeasures, we demonstrate this type of attack through a simulated experiment, where a malicious QR code directs a user to a phishing site. For our experiment, we cloned Google's web page providing access to their email service (Gmail). Since, the URL is masqueraded into the QR code the unsuspecting user who opens the URL is directed to the malicious site. Our results proved that hackers could easily leverage QR codes into phishing attack vectors targeted at smartphone users, even bypassing web browsers safe browsing feature. In addition, the second part of our paper presents adequate countermeasures and introduces QRCS (Quick Response Code Secure). QRCS is a universal efficient and effective solution focusing exclusively on the authenticity of the originator and consequently, the integrity of QR code by using digital signatures.
机译:由于很难将真正的QR码与恶意的QR码区分开,因此二维快速响应(QR)码可能会产生误导。由于该漏洞实际上是其设计的一部分,因此扫描恶意QR码可以将用户定向到克隆的恶意站点,从而揭示敏感信息。为了评估漏洞并提出后续对策,我们通过模拟实验演示了这种类型的攻击,其中恶意QR代码将用户定向到网络钓鱼站点。对于我们的实验,我们克隆了Google的网页以提供对其电子邮件服务(Gmail)的访问权限。由于URL被伪装成QR码,因此打开URL的毫无戒心的用户将被定向到恶意站点。我们的结果证明,即使绕过Web浏览器的安全浏览功能,黑客也可以轻松地将QR码用于针对智能手机用户的网络钓鱼攻击媒介。另外,本文的第二部分提出了适当的对策,并介绍了QRCS(快速响应代码安全)。 QRCS是一种通用高效的解决方案,其重点仅在于始发者的真实性,并因此通过使用数字签名来提高QR码的完整性。

著录项

  • 作者单位
  • 年度 2017
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 入库时间 2022-08-20 20:11:00

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号