• DocumentCode
    1618606
  • Title

    Visual security is feeble for anti-phishing

  • Author

    Leung, Chun-Ming

  • Author_Institution
    Dept. of Inf. Eng., Chinese Univ. of Hong Kong, Hong Kong, China
  • fYear
    2009
  • Firstpage
    118
  • Lastpage
    123
  • Abstract
    Addressing recent online banking threats, the banking industry offers us several solutions for our safety online banking experience, however those solutions may not finally secure the users under the rising threats. The main challenges are how to enable safe online banking on a compromised host, and solving the general ignorance of security warning. CAPTCHA is primarily used to anti bot automated login, also, CAPTCHA base application can further provides secure PIN input against keylogger and mouse-logger for bank´s customer. Assuming users are always unconscious of security warning in our model, we have designed a series of attacks and defenses under this interesting condition. In this work, we started by formalizing a security defense utilizing CAPCTCHA, its limitations are analyzed; Then, we attacked a local bank employing CAPTCHA solution, which we show how its can be bypassed from its vulnerability in its implementation. We further introduce control-relaying man-in-the-middle (CR-MITM) attack, a remote attack just like a remote terminal service that can capture and relay user inputs without local Trojan assistant, which is possible to defeat CAPTCHA phishing protection in the future. Under our model, we conclude, visual security defense alone is feeble for anti-phishing.
  • Keywords
    bank data processing; computer crime; message authentication; unsolicited e-mail; CAPTCHA; anti bot automated login; anti-phishing; banking industry; control-relaying man-in-the-middle attack; keylogger; mouse-logger; online banking threats; remote attack; remote terminal service; visual security; Authentication; Banking; Humans; Information security; Internet; Protection; Protective relaying; Public key; Public key cryptography; Safety; Authentication; CAPTCHA; Implementation Flaw; Man-In-The-Middle (MITM); Online Banking; Phishing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Anti-counterfeiting, Security, and Identification in Communication, 2009. ASID 2009. 3rd International Conference on
  • Conference_Location
    Hong Kong
  • Print_ISBN
    978-1-4244-3883-9
  • Electronic_ISBN
    978-1-4244-3884-6
  • Type

    conf

  • DOI
    10.1109/ICASID.2009.5276940
  • Filename
    5276940