Measuring Identity Confusion with Uniform Resource Locators

Measuring Identity Confusion with Uniform Resource Locators
复制标题

使用统一资源定位器测量身份混乱

DOI:
10.1145/3313831.3376298
复制
发表时间:
2020
期刊:
Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems
影响因子:
--
通讯作者:
Michael Bailey
Michael Bailey
中科院分区:
--
文献类型:
--
作者:
J. Reynolds;Deepak Kumar;Zane Ma;Rohan Subramanian;Meishan Wu;Martin Shelton;Joshua Mason;Emily Stark;Michael Bailey

文献摘要

被引文献

相似文献

统一资源定位器(url)在web上明确指定主机标识。url在语法上很复杂,尽管软件可以准确地从url解析身份,但用户经常暴露于url,并期望他们也这样做。不幸的是,通过URL对身份进行不正确的评估可能会使用户遭受攻击,例如输入错误和网络钓鱼。我们的工作是研究用户如何正确地从普通服务和混淆的“相似”url中确定真实url的主机身份。我们观察到参与者采用了广泛的URL解析策略,并且可以在93%的时间内识别真实的URL。然而,只有40%的混淆url被正确识别。这些错误突出了URL让用户感到困惑的几个方面,以及现有URL解析策略不足的原因。最后,我们提出了如何可靠地向用户传递网站身份的未来研究方向。
Uniform Resource Locators (URLs) unambiguously specify host identity on the web. URLs are syntactically complex, and although software can accurately parse identity from URLs, users are frequently exposed to URLs and expected to do the same. Unfortunately, incorrect assessment of identity from a URL can expose users to attacks, such as typosquatting and phishing. Our work studies how well users can correctly determine the host identity of real URLs from common services and obfuscated "look-alike" URLs. We observe that participants employ a wide range of URL parsing strategies, and can identify real URLs 93% of time. However, only 40% of obfuscated URLs were identified correctly. These mistakes highlighted several ways in which URLs were confusing to users and why their existing URL parsing strategies fall short. We conclude with future research directions for reliably conveying website identity to users.