An Empirical Approach to Phishing Countermeasures Through Smart Glasses and Validation Agents

An Empirical Approach to Phishing Countermeasures Through Smart Glasses and Validation Agents
复制标题

通过智能眼镜和验证代理进行网络钓鱼对策的实证方法

DOI:
10.1109/access.2019.2940669
复制
发表时间:
2019
期刊:
影响因子:
3.9
通讯作者:
Kadobayashi Youki
Kadobayashi Youki
中科院分区:
计算机科学3区
文献类型:
--
作者:
Ndibwile Jema David;Luhanga Edith Talina;Fall Doudou;Miyamoto Daisuke;Blanc Gregory;Kadobayashi Youki

文献摘要

相似文献

尽管学术界和工业界做出了缓解努力,但钓鱼攻击已经持续了20多年。我们认为,用户成为攻击的受害者不仅是因为缺乏知识和意识,还因为他们对访问的网页上的安全指标和视觉异常没有足够的关注。这可能也是为什么智能设备用户的屏幕尺寸和设备功能比台式机用户更有限的原因,他们成为钓鱼攻击受害者的可能性是台式机用户的三倍。为了证明我们的观点,我们首先调查了不同智能手机用户群体对网络钓鱼的普遍认知。然后,我们使用智能眼镜(眼电图仪)来实验性地测量用户在浏览网站和玩我们开发的Android网络钓鱼游戏时所表现出的精神努力和警觉性。结果显示,有关钓鱼的知识和意识似乎对安全行为没有显著影响,因为有知识的参与者表现出不安全的行为,比如打开来自陌生发件人的电子邮件附件。然而,专注力很重要,因为即使是网络安全知识较低的参与者,如果他们相当专心,也可以有效地识别攻击。基于这些结果,我们断言,除非提供了减轻身份识别负担的工具,否则用户更有可能由于不安全的行为而继续成为网络钓鱼攻击的受害者。因此,我们建议在定制的Android浏览器中实现一个轻量级算法,以便在没有用户交互的情况下欺骗性地检测钓鱼网站。我们使用虚假的登录凭据作为验证代理,并监控目的服务器的HTTP响应来确定网页的真实性。并给出了该算法的初步评价结果。
Phishing attacks have been persistent for more than two decades despite mitigation efforts from academia and industry. We believe that users fall victim to attacks not only because of lack of knowledge and awareness, but also because they are not attentive enough to security indicators and visual abnormalities on the webpages they visit. This is also probably why smart device users, who have more limited screen size and device capabilities compared to desktop users, are three times more likely to fall victim to phishing attacks. To assert our claim, we first investigated general phishing awareness among different groups of smartphone users. We then used smart eyeglasses (electro-oculographic) to experimentally measure the mental effort and vigilance exhibited by users while surfing a website and while playing an Android phishing game that we developed. The results showed that knowledge and awareness about phishing do not seem to have a significant impact on security behaviours, as knowledgeable participants exhibited insecure behaviours such as opening email attachments from unfamiliar senders. However, attentiveness was important as even participants with low cybersecurity knowledge could effectively identify attacks if they were reasonably attentive. Based on these results, we asserted that users are more likely to continue falling victim to phishing attacks due to insecure behaviours, unless tools to lessen the identification burden are provided. We thus recommended implementing a lightweight algorithm into a custom Android browser for detecting phishing sites deceptively without a user interaction. We used fake login credentials as validation agents and monitor the destination server HTTP responses to determine the authenticity of a webpage. We also presented initial evaluation results of this algorithm.