The Devil Is Phishing: Rethinking Web Single Sign-On Systems Security
The Devil Is Phishing: Rethinking Web Single Sign-On Systems Security
复制标题
网络钓鱼是魔鬼:重新思考 Web 单点登录系统安全
DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
Chuan Yue
中科院分区:
文献类型:
--
作者:
Chuan Yue
One significant trend in online user authentication is using Web Single Sign-On (SSO) systems. Especially, open Web SSO standards such as OpenID and OAuth are rapidly gaining adoption on the Web, and they enable over one billion user accounts. However, the largescale threat from phishing attacks to real-world Web SSO systems has been significantly underestimated and insufficiently analyzed. In this paper, we (1) pinpoint what are really unique in Web SSO phishing, (2) provide one example to illustrate how the identity providers (IdPs) of Web SSO systems can be spoofed with ease and precision, (3) present a preliminary user study to demonstrate the high effectiveness (20 out of 28, or 71% of participants became “victims”) of Web SSO phishing attacks, and (4) call for a collective effort to effectively defend against the insidious Web SSO phishing attacks.