2005
|
Sign up to set email alerts
Visual Spoofing of SSL Protected Web Sites and Effective Countermeasures
Search citation statements
Order By: Relevance
Paper Sections
Select...
30
4
3
0
Citation Types
0
49
0
0
Year Published
Range
2005
20052022
2022Publication Types
Select...
14
11
8
Relationship
3
30
Authors
Journals
Cited by 33 publications
(49 citation statements)
References 5 publications
0
49
0
0
Order By: Relevance
Abstract
Smart CitationsHow this paper cites the one you are viewing
“…From a user's perspective, we believe that, even without requiring any new user actions, it can be useful for some users to see in which country a server is locatedwhether this information is verified by SLV or just asserted by any browser plugin, e.g., flagfox (see Section 8). In a phishing attack, if the adversary obtains a valid certificate for a spoofed domain, standard visual browser cues will show green locks, and positively assuring symbols [46]. A country's flag or a displayed world map will however differ from expectations (i.e., when the adversary's fraudulent machine is hosted remotely).…”
Section: Discussion
mentioning
confidence: 99%
Abstract
Smart CitationsHow this paper cites the one you are viewing
“…From a user's perspective, we believe that, even without requiring any new user actions, it can be useful for some users to see in which country a server is locatedwhether this information is verified by SLV or just asserted by any browser plugin, e.g., flagfox (see Section 8). In a phishing attack, if the adversary obtains a valid certificate for a spoofed domain, standard visual browser cues will show green locks, and positively assuring symbols [46]. A country's flag or a displayed world map will however differ from expectations (i.e., when the adversary's fraudulent machine is hosted remotely).…”
Section: Discussion
mentioning
confidence: 99%
Smart CitationsHow this paper cites the one you are viewing
“…In this work, we have presented the dangers inherent to an excessive trust into the SSL/TLS indicators, i.e., unsuspecting users blindly trusting a webpage when it advertises its use of an SSL/TLS certificate. Security indicators, such as the padlock icon, have been criticized in the past to be difficult to interpret by users as they often lack the knowledge of security indicators [23], and are now more confusing to them since they are also misused by attackers to convey a false sense of security [24]. Mobile users are even more oblivious of their presence when dealing with the reduced screens of their smartphones [25].…”
Section: Discussion
mentioning
confidence: 99%
Abstract
Smart CitationsHow this paper cites the one you are viewing
“…Personal Authentication solution 11, as in Sub‐path 3 of our trust model, requires that PCs have personal folders with individually chosen background bitmaps. This is not inappropriate for users using a PC at an Internet Cafe.…”
Section: Discussion
mentioning
confidence: 99%
“…Since ADSI may randomly choose a picture, and embed it into the current web browser at the random place, an adversary cannot predict it, thus the attacker cannot spoof the randomly embedded indicator. Compared with a familiar image of the user 11, a randomly embedded image is not quite attractive to the user. The ignorance of the user can be compensated by the automatic checking mechanism of our ADSI, as it will alarm the user in any way upon detecting a mismatch.…”
Section: Discussion
mentioning
confidence: 99%
“…To this end, we propose a simple and effective way in protecting naive users from pop‐up browser spoofing attacks. As the spoofing techniques evolve, and are used jointly, we can see that our method cannot defend against them without accommodating other security mechanisms such as personal image 11 and TCA 10. Fortunately, aforementioned ADSI does not conflict with any other security means, but compensates with them.…”
Section: Discussion
mentioning
confidence: 99%
Abstract
Smart CitationsHow this paper cites the one you are viewing
“…From a user's perspective, we believe that, even without requiring any new user actions, it can be useful for some users to see in which country a server is locatedwhether this information is verified by SLV or just asserted by any browser plugin, e.g., flagfox (see Section 8). In a phishing attack, if the adversary obtains a valid certificate for a spoofed domain, standard visual browser cues will show green locks, and positively assuring symbols [46]. A country's flag or a displayed world map will however differ from expectations (i.e., when the adversary's fraudulent machine is hosted remotely).…”
Section: Discussion
mentioning
confidence: 99%
Smart CitationsHow this paper cites the one you are viewing
“…In this work, we have presented the dangers inherent to an excessive trust into the SSL/TLS indicators, i.e., unsuspecting users blindly trusting a webpage when it advertises its use of an SSL/TLS certificate. Security indicators, such as the padlock icon, have been criticized in the past to be difficult to interpret by users as they often lack the knowledge of security indicators [23], and are now more confusing to them since they are also misused by attackers to convey a false sense of security [24]. Mobile users are even more oblivious of their presence when dealing with the reduced screens of their smartphones [25].…”
Section: Discussion
mentioning
confidence: 99%
Abstract
Smart CitationsHow this paper cites the one you are viewing
“…Personal Authentication solution 11, as in Sub‐path 3 of our trust model, requires that PCs have personal folders with individually chosen background bitmaps. This is not inappropriate for users using a PC at an Internet Cafe.…”
Section: Discussion
mentioning
confidence: 99%
“…Since ADSI may randomly choose a picture, and embed it into the current web browser at the random place, an adversary cannot predict it, thus the attacker cannot spoof the randomly embedded indicator. Compared with a familiar image of the user 11, a randomly embedded image is not quite attractive to the user. The ignorance of the user can be compensated by the automatic checking mechanism of our ADSI, as it will alarm the user in any way upon detecting a mismatch.…”
Section: Discussion
mentioning
confidence: 99%
“…To this end, we propose a simple and effective way in protecting naive users from pop‐up browser spoofing attacks. As the spoofing techniques evolve, and are used jointly, we can see that our method cannot defend against them without accommodating other security mechanisms such as personal image 11 and TCA 10. Fortunately, aforementioned ADSI does not conflict with any other security means, but compensates with them.…”
Section: Discussion
mentioning
confidence: 99%
Abstract
Smart CitationsHow this paper cites the one you are viewing
“…From a user's perspective, we believe that, even without requiring any new user actions, it can be useful for some users to see in which country a server is locatedwhether this information is verified by SLV or just asserted by any browser plugin, e.g., flagfox (see Section 8). In a phishing attack, if the adversary obtains a valid certificate for a spoofed domain, standard visual browser cues will show green locks, and positively assuring symbols [46]. A country's flag or a displayed world map will however differ from expectations (i.e., when the adversary's fraudulent machine is hosted remotely).…”
Section: Discussion
mentioning
confidence: 99%
Smart CitationsHow this paper cites the one you are viewing
“…In this work, we have presented the dangers inherent to an excessive trust into the SSL/TLS indicators, i.e., unsuspecting users blindly trusting a webpage when it advertises its use of an SSL/TLS certificate. Security indicators, such as the padlock icon, have been criticized in the past to be difficult to interpret by users as they often lack the knowledge of security indicators [23], and are now more confusing to them since they are also misused by attackers to convey a false sense of security [24]. Mobile users are even more oblivious of their presence when dealing with the reduced screens of their smartphones [25].…”
Section: Discussion
mentioning
confidence: 99%
Abstract
Smart CitationsHow this paper cites the one you are viewing
“…Personal Authentication solution 11, as in Sub‐path 3 of our trust model, requires that PCs have personal folders with individually chosen background bitmaps. This is not inappropriate for users using a PC at an Internet Cafe.…”
Section: Discussion
mentioning
confidence: 99%
“…Since ADSI may randomly choose a picture, and embed it into the current web browser at the random place, an adversary cannot predict it, thus the attacker cannot spoof the randomly embedded indicator. Compared with a familiar image of the user 11, a randomly embedded image is not quite attractive to the user. The ignorance of the user can be compensated by the automatic checking mechanism of our ADSI, as it will alarm the user in any way upon detecting a mismatch.…”
Section: Discussion
mentioning
confidence: 99%
“…To this end, we propose a simple and effective way in protecting naive users from pop‐up browser spoofing attacks. As the spoofing techniques evolve, and are used jointly, we can see that our method cannot defend against them without accommodating other security mechanisms such as personal image 11 and TCA 10. Fortunately, aforementioned ADSI does not conflict with any other security means, but compensates with them.…”
Section: Discussion
mentioning
confidence: 99%