DocumentCode
2414605
Title
Compartmented Security for Browsers - Or How to Thwart a Phisher with Trusted Computing
Author
Gajek, Sebastian ; Sadeghi, Ahmad-Reza ; Stüble, Christian ; Winandy, Marcel
Author_Institution
Horst Gortz Inst. for IT Security, Ruhr-Univ. Bochum
fYear
2007
fDate
10-13 April 2007
Firstpage
120
Lastpage
127
Abstract
Identity theft through phishing attacks has become a major concern for Internet users. Typically, phishing attacks aim at luring the user to a faked Web site to disclose personal information. Existing solutions proposed against this kind of attack can, however, hardly counter the new generation of sophisticated malware phishing attacks, e.g., pharming Trojans, designed to target certain services. This paper aims at making the first steps towards the design and implementation of a security architecture that prevents both classical and malware phishing attacks. Our approach is based on the ideas of compartmentalization for isolating applications of different trust level, and a trusted wallet for storing credentials and authenticating sensitive services. Once the wallet has been setup in an initial step, our solution requires no special care from users for identifying the right Web sites while the disclosure of credentials is strictly controlled. Moreover, a prototype of the basic platform exists and we briefly describe its implementation
Keywords
Internet; Web sites; invasive software; online front-ends; Internet; Web sites; compartmented browser security; identity theft; malware phishing attacks; personal information disclosure; trusted computing; Authentication; Computer crime; Counting circuits; Credit cards; Information security; Operating systems; Protection; Prototypes; Web and internet services; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security, 2007. ARES 2007. The Second International Conference on
Conference_Location
Vienna
Print_ISBN
0-7695-2775-2
Type
conf
DOI
10.1109/ARES.2007.59
Filename
4159795
Link To Document