首页> 外文会议>International Conference on Financial Cryptography and Data Security >An Evaluation of Extended Validation and Picture-in-Picture Phishing Attacks
【24h】

An Evaluation of Extended Validation and Picture-in-Picture Phishing Attacks

机译:对扩展验证和图片in-in-picture网络钓鱼攻击的评估

获取原文

摘要

In this usability study of phishing attacks and browser anti-phishing defenses, 27 users each classified 12 web sites as fraudulent or legitimate. By dividing these users into three groups, our controlled study measured both the effect of extended validation certificates that appear only at legitimate sites and the effect of reading a help file about security features in Internet Explorer 7. Across all groups, we found that picture-in-picture attacks showing a fake browser window were as effective as the best other phishing technique, the homograph attack. Extended validation did not help users identify either attack. Additionally, reading the help file made users more likely to classify both real and fake web sites as legitimate when the phishing warning did not appear.
机译:在这种可用性研究网络钓鱼攻击和浏览器反网络钓鱼防御中,27个用户每个分类为12个网站,欺诈或合法。通过将这些用户划分为三组,我们的受控研究既可测量只在合法站点出现的扩展验证证书的效果,以及在所有组中读取关于Internet Explorer中的安全功能的帮助文件。在所有组中,我们发现了图片 - 显示假浏览器窗口的图像内攻击与最佳其他网络钓鱼技术一样有效,同情攻击。扩展验证没有帮助用户识别任何攻击。此外,读取帮助文件使用户更有可能在未出现网络钓鱼警告时将真实和假网站分类为合法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号