DocumentCode
2877304
Title
Multilingual web sites: Internationalized Domain Name homograph attacks
Author
Al Helou, Johnny ; Tilley, Scott
Author_Institution
Dept. of Comput. Sci., Florida Inst. of Technol., Melbourne, FL, USA
fYear
2010
fDate
17-18 Sept. 2010
Firstpage
89
Lastpage
92
Abstract
Homograph attacks are a very common type of security vulnerability on the Web. The attack aims to hide the domain name origin by switching some letters in the URL. As the Web evolves beyond the traditional base of English-speaking users, this kind of threat will increase significantly with the use of non-Latin scripts in the entire domain name. The recent introduction of Internationalized Domain Names (IDN) country-code Top Level Domains (ccTLDs) adaptation has made this new homograph attack possible. This paper outlines some of the possible security risks from using non-Latin scripts in the domain name, using examples drawn from Arabic, including the confusion from transforming the non-Latin scripts to ASCII compatible Encoding (ACE). The paper describes some of the existing defenses against IDN homograph attacks, such as white listing of domains and algorithmic analysis of the scripts in the URL. A preliminary design for a new client-side approach to the problem is also outlined. The approach focuses on drawing the user´s attention to possible threats when browsing a non-Latin Web site. Some of the techniques being considered include Punycode generation and comparison, highlighting confusing letters (including increasing font sizes for Arabic script), and pre-fetching thumbnail images of Web pages. These solutions will not prevent the attack, but they can provide a visual defense to the user in an unobtrusive and easily adoptable manner.
Keywords
Web sites; computer crime; natural language processing; ASCII compatible encoding; Homograph attacks; URL; Web pages; algorithmic analysis; client-side approach; country-code top level domains adaptation; domain name origin; internationalized domain names; multilingual Web sites; prefetching thumbnail images; punycode generation; security vulnerability; Browsers; Encoding; Fires; Internet; Security; Visualization; Web sites; IDN; IDNccTLD; Web site; attack; homograph; international; multilingual; phishing; security;
fLanguage
English
Publisher
ieee
Conference_Titel
Web Systems Evolution (WSE), 2010 12th IEEE International Symposium on
Conference_Location
Timisoara
ISSN
1550-4441
Print_ISBN
978-1-4244-8638-0
Type
conf
DOI
10.1109/WSE.2010.5623562
Filename
5623562
Link To Document