Using one-time passwords to prevent password phishing attacks

被引:28
作者
Huang, Chun-Ying [1 ]
Ma, Shang-Pin [1 ]
Chen, Kuan-Ta [2 ]
机构
[1] Natl Taiwan Ocean Univ, Dept Comp Sci & Engn, Keelung 202, Taiwan
[2] Acad Sinica, Inst Informat Sci, Sect 2, Taipei 115, Taiwan
关键词
Anti-phishing; Identity management; In-band password delivery; One-time password; Web security;
D O I
10.1016/j.jnca.2011.02.004
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing is now a serious threat to the security of Internet users' confidential information. Basically, an attacker (phisher) tricks people into divulging sensitive information by sending fake messages to a large number of users at random. Unsuspecting users who follow the instruction in the messages are directed to well-built spoofed web pages and asked to provide sensitive information, which the phisher then steals. Based on our observations, more than 70% of phishing activities are designed to steal users' account names and passwords. With such information, an attacker can retrieve more valuable information from the compromised accounts. Statistics published by the anti-phishing working group (APWG) show that, at the end of Q2 in 2008, the number of malicious web pages designed to steal users' passwords had increased by 258% over the same period in 2007. Therefore, protecting users from phishing attacks is extremely important. A naive way to prevent the theft of passwords is to avoid using passwords. This raises the following question: Is it possible to authenticate a user without a preset password? In this paper, we propose a practical authentication service that eliminates the need for preset user passwords during the authentication process. By leveraging existing communication infrastructures on the Internet, i.e., the instant messaging service, it is only necessary to deploy the proposed scheme on the server side. We also show that the proposed solution can be seamlessly integrated with the OpenID service so that websites supporting OpenID benefit directly from the proposed solution. The proposed solution can be deployed incrementally, and it does not require client-side scripts, plug-ins, nor external devices. We believe that the number of phishing attacks could be reduced substantially if users were not required to provide their own passwords when accessing web pages. (C) 2011 Elsevier Ltd. All rights reserved.
引用
收藏
页码:1292 / 1301
页数:10
相关论文
共 55 条
[11]  
BASET SA, 2004, CSNI0412017 ARXIV
[12]  
*BIN IN LLC, 2009, AIM ENCR FREE SEC CE
[13]  
CHEN KT, 2009, IEEE INTERNET CO MAY, P30
[14]  
Chou Neil., 2004, NDSS 04
[15]  
CRANOR L, 2007, NDSS 07
[16]  
DANCHEV D, 2008, DIY PHISHING KITS IN
[17]  
DHAMIJA R, 2006, CHI 06, P581
[18]   Detecting phishing web pages with visual similarity assessment based on Earth Mover's Distance (EMD) [J].
Fu, Anthony Y. ;
Wenyin, Liu ;
Deng, Xiaotie .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2006, 3 (04) :301-311
[19]  
*GOOGL INC, 2007, GOOGL SAF BROWS FIR
[20]  
*GOOGL INC, 2009, OP COMM GOOGL TALK D