Most of the $37 million increase in losses from Internet fraud observed between 2001 to 2002 has been attributed to web spoofing [Von03]. While web spoofing (or phishing) may become more sophisticated in the future, we propose a set of methods that appear effective for the kind of simple attacks observed by law enforcement and affected companies. SpoofGuard uses a combinationofstatelesspageevaluation, statefulpageevaluation, and examination of outgoing post data to computer a spoof index. When a user enters a username and password on a spoof site that contains some combination of suspicious url, misleading domain name, images from an honest site, other measures discussed in section 3, and a username and password that have previously been
usedatanhonestsite, SpoofGuard will intercept the post and warn the user with a pop-up that foils the attack. We have tested SpoofGuard with actual attacks found in the wild and found the mechanisms generally unobtrusive and effective. While technically savvy Internet professionals probably do not need SpoofGuard themselves, there are many less sophisticated users who may benefit from this tool.
Most of the $37 million increase in losses from Internet fraud observed between 2001 to 2002 has been attributed to web spoofing [Von03]. While web spoofing (or phishing) may become more sophisticated in the future, we propose a set of methods that appear effective for the kind of simple attacks observed by law enforcement and affected companies. SpoofGuard uses a combinationofstatelesspageevaluation, statefulpageevaluation, and examination of outgoing post data to computer a spoof index. When a user enters a username and password on a spoof site that contains some combination of suspicious url, misleading domain name, images from an honest site, other measures discussed in section 3, and a username and password that have previously beenusedatanhonestsite, SpoofGuard will intercept the post and warn the user with a pop-up that foils the attack. We have tested SpoofGuard with actual attacks found in the wild and found the mechanisms generally unobtrusive and effective. While technically savvy Internet professionals probably do not need SpoofGuard themselves, there are many less sophisticated users who may benefit from this tool.
การแปล กรุณารอสักครู่..
