Uploaded by 0Oooo0oO0ooOoo0 on May 4, 2011
Defending against Phishing without Client-side Code
We study defenses against phishing websites, which do not require installation of any software on the client side. The two main website defenses we discuss, are server identification e.g. using secret images, and the usage of bookmarks and/or cookies as a secondary form of authentication. We discuss the design of such server-only defenses, and results of experimental studies of security and usability.
Usability studies show that server-identification, e.g. by an image or text displayed in the login page, can provide a modest improvement in the detection rates of spoofed sites. We found an improvement in detection rates, when the user was actively involved in the image selection and display (e.g. if user must click on the image).
However, server-identifiers must be protected from exposure; this is usually achieved by some form of secondary user authentication, most commonly using cookies and/or bookmarks. We discuss these options. In particular, we show two possible advantages from using bookmarks to provide secondary user identification: improved defense against phishing, in particular against phishing emails and phishing by links, e.g. of search engine results; and ability to protect the authentication secrets against eavesdroppers and spoofed servers.
Bio
Prof. Amir Herzberg received B.Sc. (Computer Engineering), M.Sc. (Electrical Engineering) and D.Sc. (Computer Science), from the Technion, Israel, at 1982, 1987 and 1991, respectively. Since 1982, he worked in software and systems R&D, mostly in security and networking, as developer, manager and CTO, in few companies. During 1991-2000, Prof. Herzberg filled research and management positions in IBM Research (New York and Israel). Since 2002, he is an associate professor in the Computer Science department of Bar Ilan University. His current research interests include security of communication and commerce, quality of service, vehicular and ad-hoc networking, and applied cryptography
http://www.owasp.org/index.php/OWASP_Israel_2008_Conference_at_the_Interdisci...
-
1 likes, 0 dislikes
12:10
MODERN SYSTEM ANALYSIS & DESIGN TUTORIAL CHAPTER 14by javaaykut119 views
5:49
ערב חדש - התקפה על מערכת הבחירות החדשה של ישראלby 0Oooo0oO0ooOoo076 views
37:53
Shai Chen: Achilles' heel -- Hacking Through Java Protocols (in Hebrew)by 0Oooo0oO0ooOoo0147 views
47:35
Ofer Shezaf : Trends in Web Hacking: What's hot in 2008 (in Hebrew)by 0Oooo0oO0ooOoo0115 views
8:31
OWASP Appsec Tutorial Series - Episode 1: Appsec Basicsby AppsecTutorialSeries22,299 views
4:52
Internet Symphony with Cowbellby 0Oooo0oO0ooOoo035 views
1:50
Israeli e-voting RFID card zapperby 0Oooo0oO0ooOoo03,885 views
1:37
CISCO Networkingby bakercollegeTV13,568 views
2:30
Client Management Tipsby AccountancyAge503 views
43:16
Ivan Ristic: No More Signatures: Defending Web Applications from 0-Day Attacks with ModProfiler Usinby 0Oooo0oO0ooOoo0307 views
0:02
CATIA: Von Mises Stress at Generative Structural Analysisby agusfikri6,556 views
1:00:33
Lecture - 16by nptelhrd5,099 views
9:55
Leandro Fleischer interviews and debates Amir Weitmann about Liberalism and Religion (Hebrew)by FreedomLeandro52 views
4:08
amir hebrew fixed internetby amirnano29 views
3:19
Amir Blumenfeld: The Truth About Jewish Summer Campsby myjewishlearning62,961 views
2:42
Translator (Jake and Amir)by collegehumor530,626 views
0:48
Re: Jake and Amir: Hebrewby cappy973,287 views
0:21
Amir singing in Hebrew at the High St. Stationby jeffbakersfield44 views
3:43
Amir Benayun - I have a dream עמיר בניון - יש לי חלוםby Yodel83IL2,915 views
6:02
Hebrew University researcher Amir Amedi: Legacy of Inspiring Mindsby elscvideo469 views
- Loading more suggestions...
Link to this comment:
All Comments (0)