iTrustPage: A User-Assisted Anti-Phishing Tool

被引:0
作者
Ronda, Troy [1 ]
Saroiu, Stefan [1 ]
Wolman, Alec
机构
[1] Univ Toronto, Dept Comp Sci, Toronto, ON M5S 1A1, Canada
来源
EUROSYS'08: PROCEEDINGS OF THE EUROSYS 2008 CONFERENCE | 2008年
关键词
phishing; anti-phishing;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Despite the many solutions proposed by industry and the research community to address phishing attacks, this problem continues to cause enormous damage. Because of our inability to deter phishing attacks, the research community needs to develop new approaches to anti-phishing solutions. Most of today's anti-phishing technologies focus on automatically detecting and preventing phishing attacks. While automation makes anti-phishing tools user-friendly, automation also makes them suffer from false positives, false negatives, and various practical hurdles. As a result, attackers often find simple ways to escape automatic detection. This paper presents iTrustPage - an anti-phishing tool that does not rely completely on automation to detect phishing. Instead, iTrustPage relies on user input and external repositories of information to prevent users from filling out phishing Web forms. With iTrustPage, users help to decide whether or not a Web page is legitimate. Because iTrustPage is user-assisted, iTrustPage avoids the false positives and the false negatives associated with automatic phishing detection. We implemented iTrustPage as a downloadable extension to FireFox. After being featured on the Mozilla website for FireFox extensions, iTrustPage was downloaded by more than 5,000 users in a two week period. We present an analysis of our tool's effectiveness and ease of use based oil our examination of usage logs collected from the 2,050 users who used iTrustPage for more than two weeks. Based on these logs, we find that iTrustPage disrupts users on fewer than 2% of the pages they visit, and the number of disruptions decreases over time.
引用
收藏
页码:261 / 272
页数:12
相关论文
共 29 条
[1]  
[Anonymous], 2006, ASIACCS
[2]  
[Anonymous], P C HUM FACT COMP SY
[3]  
CHIASSON S, 2006, P USENIX SEC S AUG
[4]  
*CNET NEWS COM, NEW TOOL EN SOPH PHI
[5]  
DOWNS JS, 2006, P S US PRIV SEC JUL
[6]  
Fette I., 2007, P INT WORLD WID WEB
[7]  
Florencio D., 2006, P USENIX WORKSH HOT
[8]  
Florencio Dinei, 2007, P INT WORLD WID WEB
[9]  
FRANCO R, 2005, BETTER WEBSITE IDENT
[10]  
HALDERMAN J, 2005, P INT C WORLD WID WE