The Experts below are selected from a list of 51 Experts worldwide ranked by ideXlab platform

Duminda Wijesekera - One of the best experts on this subject based on the ideXlab platform.

  • voice Pharming Attack and the trust of voip
    International Workshop on Security, 2008
    Co-Authors: Xinyuan Wang, Ruishan Zhang, Xiaohui Yang, Xuxian Jiang, Duminda Wijesekera
    Abstract:

    Voice communication is fundamental to the normal operation of our society. The general public have put a lot of trust in voice communication and they have been relying on it for many critical and sensitive information exchange (e.g., emergency 911 calls, calls to customer service of financial institutions). Now more and more voice calls are carried, at least partially, over the public Internet rather than traditional Public Switched Telephone Network (PSTN). The security ramifications of using VoIP, however, have not been fully recognized. It is not clear how secure and trustworthy the currently deployed VoIP systems are, and there exists a substantial gap in the understanding of the potential impact of VoIP exploits on the VoIP users. In this paper, we seek to fill this gap by investigating the trust issues of currently deployed VoIP systems and their implications to the VoIP users. Our experiments with leading deployed VoIP services (e.g, Vonage, ATT 2) redirect any selected Vonage and ATT 3) manipulate and set the call forwarding setting of any selected Gizmo VoIP subscriber without authorization. Such an unauthorized call diversion capability enables a new Attack, called voice Pharming, against VoIP users, where the Attacker transparently diverts selected VoIP calls to the bogus IVR (interactive voice response) or bogus representative. In other words, voice Pharming can cause selected VoIP callers to interact with the bogus IVR or representative even if they have dialed the correct phone numbers. Therefore, even the most meticulous VoIP caller could be tricked into giving out sensitive information (e.g., SSN, credit card number, PIN) to the adversary. To mitigate such imminent threats to current VoIP users, all segments along the VoIP path need to be protected and trustworthy. Our experience shows that enforcing TLS or IPSEC between the SIP phone and SIP servers could be an effective first step toward mitigation.

  • SecureComm - Voice Pharming Attack and the trust of VoIP
    Proceedings of the 4th international conference on Security and privacy in communication netowrks - SecureComm '08, 2008
    Co-Authors: Xinyuan Wang, Ruishan Zhang, Xiaohui Yang, Xuxian Jiang, Duminda Wijesekera
    Abstract:

    Voice communication is fundamental to the normal operation of our society. The general public have put a lot of trust in voice communication and they have been relying on it for many critical and sensitive information exchange (e.g., emergency 911 calls, calls to customer service of financial institutions). Now more and more voice calls are carried, at least partially, over the public Internet rather than traditional Public Switched Telephone Network (PSTN). The security ramifications of using VoIP, however, have not been fully recognized. It is not clear how secure and trustworthy the currently deployed VoIP systems are, and there exists a substantial gap in the understanding of the potential impact of VoIP exploits on the VoIP users. In this paper, we seek to fill this gap by investigating the trust issues of currently deployed VoIP systems and their implications to the VoIP users. Our experiments with leading deployed VoIP services (e.g, Vonage, ATT 2) redirect any selected Vonage and ATT 3) manipulate and set the call forwarding setting of any selected Gizmo VoIP subscriber without authorization. Such an unauthorized call diversion capability enables a new Attack, called voice Pharming, against VoIP users, where the Attacker transparently diverts selected VoIP calls to the bogus IVR (interactive voice response) or bogus representative. In other words, voice Pharming can cause selected VoIP callers to interact with the bogus IVR or representative even if they have dialed the correct phone numbers. Therefore, even the most meticulous VoIP caller could be tricked into giving out sensitive information (e.g., SSN, credit card number, PIN) to the adversary. To mitigate such imminent threats to current VoIP users, all segments along the VoIP path need to be protected and trustworthy. Our experience shows that enforcing TLS or IPSEC between the SIP phone and SIP servers could be an effective first step toward mitigation.

Cliff C. Zou - One of the best experts on this subject based on the ideXlab platform.

  • PwdIP-Hash A Lightweight Solution to Phishing and Pharming Attacks
    2013
    Co-Authors: Baber Aslam, Cliff C. Zou
    Abstract:

    Abstract—We present a novel lightweight password-based solution that safeguards users from Phishing and Pharming Attacks. The proposed authentication relies on a hashed password, which is the hash value of the user-typed password and the authentication server’s IP address. The solution rests on the fact that the server connected by a client using TCP connection cannot lie about its IP address. If a user is unknowingly directed to a malicious server (by a Phishing or a Pharming Attack), the password obtained by the malicious server will be the hashedpassword (tied to the malicious server’s IP address) and will not be usable by the Attacker at the real server thus defeating Phishing/Pharming Attack. The proposed solution does not increase the number of exchanged authentication messages, nor does it need hardware tokens as required by some previously proposed solutions. The solution is also safe against denial-ofservice Attacks since no state is maintained on server side during the authentication process. We have prototyped our design both as a web browser’s plug-in and as a standalone application. A comprehensive user study was conducted. The results show that around 95 % of users think the proposed solution is easy to use and manage. Further, around 79 % of users have shown willingness to use the application to protect their passwords. Keywords- design; web security; usability; Phishing; Pharming; password authenticatio

  • NCA - PwdIP-Hash: A Lightweight Solution to Phishing and Pharming Attacks
    2010 Ninth IEEE International Symposium on Network Computing and Applications, 2010
    Co-Authors: Baber Aslam, Cliff C. Zou
    Abstract:

    We present a novel lightweight password-based solution that safeguards users from Phishing and Pharming Attacks. The proposed authentication relies on a hashed password, which is the hash value of the user-typed password and the authentication server’s IP address. The solution rests on the fact that the server connected by a client using TCP connection cannot lie about its IP address. If a user is unknowingly directed to a malicious server (by a Phishing or a Pharming Attack), the password obtained by the malicious server will be the hashed-password (tied to the malicious server’s IP address) and will not be usable by the Attacker at the real server thus defeating Phishing/Pharming Attack. The proposed solution does not increase the number of exchanged authentication messages, nor does it need hardware tokens as required by some previously proposed solutions. The solution is also safe against denial-of-service Attacks since no state is maintained on server side during the authentication process. We have prototyped our design both as a web browser’s plug-in and as a standalone application. A comprehensive user study was conducted. The results show that around 95% of users think the proposed solution is easy to use and manage. Further, around 79% of users have shown willingness to use the application to protect their passwords.

Xinyuan Wang - One of the best experts on this subject based on the ideXlab platform.

  • voice Pharming Attack and the trust of voip
    International Workshop on Security, 2008
    Co-Authors: Xinyuan Wang, Ruishan Zhang, Xiaohui Yang, Xuxian Jiang, Duminda Wijesekera
    Abstract:

    Voice communication is fundamental to the normal operation of our society. The general public have put a lot of trust in voice communication and they have been relying on it for many critical and sensitive information exchange (e.g., emergency 911 calls, calls to customer service of financial institutions). Now more and more voice calls are carried, at least partially, over the public Internet rather than traditional Public Switched Telephone Network (PSTN). The security ramifications of using VoIP, however, have not been fully recognized. It is not clear how secure and trustworthy the currently deployed VoIP systems are, and there exists a substantial gap in the understanding of the potential impact of VoIP exploits on the VoIP users. In this paper, we seek to fill this gap by investigating the trust issues of currently deployed VoIP systems and their implications to the VoIP users. Our experiments with leading deployed VoIP services (e.g, Vonage, ATT 2) redirect any selected Vonage and ATT 3) manipulate and set the call forwarding setting of any selected Gizmo VoIP subscriber without authorization. Such an unauthorized call diversion capability enables a new Attack, called voice Pharming, against VoIP users, where the Attacker transparently diverts selected VoIP calls to the bogus IVR (interactive voice response) or bogus representative. In other words, voice Pharming can cause selected VoIP callers to interact with the bogus IVR or representative even if they have dialed the correct phone numbers. Therefore, even the most meticulous VoIP caller could be tricked into giving out sensitive information (e.g., SSN, credit card number, PIN) to the adversary. To mitigate such imminent threats to current VoIP users, all segments along the VoIP path need to be protected and trustworthy. Our experience shows that enforcing TLS or IPSEC between the SIP phone and SIP servers could be an effective first step toward mitigation.

  • SecureComm - Voice Pharming Attack and the trust of VoIP
    Proceedings of the 4th international conference on Security and privacy in communication netowrks - SecureComm '08, 2008
    Co-Authors: Xinyuan Wang, Ruishan Zhang, Xiaohui Yang, Xuxian Jiang, Duminda Wijesekera
    Abstract:

    Voice communication is fundamental to the normal operation of our society. The general public have put a lot of trust in voice communication and they have been relying on it for many critical and sensitive information exchange (e.g., emergency 911 calls, calls to customer service of financial institutions). Now more and more voice calls are carried, at least partially, over the public Internet rather than traditional Public Switched Telephone Network (PSTN). The security ramifications of using VoIP, however, have not been fully recognized. It is not clear how secure and trustworthy the currently deployed VoIP systems are, and there exists a substantial gap in the understanding of the potential impact of VoIP exploits on the VoIP users. In this paper, we seek to fill this gap by investigating the trust issues of currently deployed VoIP systems and their implications to the VoIP users. Our experiments with leading deployed VoIP services (e.g, Vonage, ATT 2) redirect any selected Vonage and ATT 3) manipulate and set the call forwarding setting of any selected Gizmo VoIP subscriber without authorization. Such an unauthorized call diversion capability enables a new Attack, called voice Pharming, against VoIP users, where the Attacker transparently diverts selected VoIP calls to the bogus IVR (interactive voice response) or bogus representative. In other words, voice Pharming can cause selected VoIP callers to interact with the bogus IVR or representative even if they have dialed the correct phone numbers. Therefore, even the most meticulous VoIP caller could be tricked into giving out sensitive information (e.g., SSN, credit card number, PIN) to the adversary. To mitigate such imminent threats to current VoIP users, all segments along the VoIP path need to be protected and trustworthy. Our experience shows that enforcing TLS or IPSEC between the SIP phone and SIP servers could be an effective first step toward mitigation.

Tawfiq S. Barhoom - One of the best experts on this subject based on the ideXlab platform.

  • Client – Side Pharming Attacks Detection using Authoritative Domain Name Servers
    2015
    Co-Authors: Ibrahim S. Alfayoumi, Tawfiq S. Barhoom
    Abstract:

    Pharming Attacks can be performed at the client-side or into the internet. In Pharming Attack, Attackers need not targeting individual user. If Pharming is performed by modifying the DNS entries, than it will be affecting to all users who is accessing the web page through that DNS. We propose an approach to protect user at client-side from Pharming Attacks by comparing IP addresses, using information provided by local DNS server and a list of IP's provided by the domain's Authenticated Name Servers which are the most trusted DNS servers for a domain

  • Client – Side Pharming Attacks Detection using Authoritative Domain Name Servers
    International Journal of Computer Applications, 2015
    Co-Authors: Ibrahim S. Alfayoumi, Tawfiq S. Barhoom
    Abstract:

    Pharming Attacks can be performed at the client-side or into the internet. In Pharming Attack, Attackers need not targeting individual user. If Pharming is performed by modifying the DNS entries, than it will be affecting to all users who is accessing the web page through that DNS. We propose an approach to protect user at client-side from Pharming Attacks by comparing IP addresses, using information provided by local DNS server and a list of IP's provided by the domain's Authenticated Name Servers which are the most trusted DNS servers for a domain. General Terms DNS security, DNS queries, DNS Poisoning, Pharming Attacks

Baber Aslam - One of the best experts on this subject based on the ideXlab platform.

  • PwdIP-Hash A Lightweight Solution to Phishing and Pharming Attacks
    2013
    Co-Authors: Baber Aslam, Cliff C. Zou
    Abstract:

    Abstract—We present a novel lightweight password-based solution that safeguards users from Phishing and Pharming Attacks. The proposed authentication relies on a hashed password, which is the hash value of the user-typed password and the authentication server’s IP address. The solution rests on the fact that the server connected by a client using TCP connection cannot lie about its IP address. If a user is unknowingly directed to a malicious server (by a Phishing or a Pharming Attack), the password obtained by the malicious server will be the hashedpassword (tied to the malicious server’s IP address) and will not be usable by the Attacker at the real server thus defeating Phishing/Pharming Attack. The proposed solution does not increase the number of exchanged authentication messages, nor does it need hardware tokens as required by some previously proposed solutions. The solution is also safe against denial-ofservice Attacks since no state is maintained on server side during the authentication process. We have prototyped our design both as a web browser’s plug-in and as a standalone application. A comprehensive user study was conducted. The results show that around 95 % of users think the proposed solution is easy to use and manage. Further, around 79 % of users have shown willingness to use the application to protect their passwords. Keywords- design; web security; usability; Phishing; Pharming; password authenticatio

  • NCA - PwdIP-Hash: A Lightweight Solution to Phishing and Pharming Attacks
    2010 Ninth IEEE International Symposium on Network Computing and Applications, 2010
    Co-Authors: Baber Aslam, Cliff C. Zou
    Abstract:

    We present a novel lightweight password-based solution that safeguards users from Phishing and Pharming Attacks. The proposed authentication relies on a hashed password, which is the hash value of the user-typed password and the authentication server’s IP address. The solution rests on the fact that the server connected by a client using TCP connection cannot lie about its IP address. If a user is unknowingly directed to a malicious server (by a Phishing or a Pharming Attack), the password obtained by the malicious server will be the hashed-password (tied to the malicious server’s IP address) and will not be usable by the Attacker at the real server thus defeating Phishing/Pharming Attack. The proposed solution does not increase the number of exchanged authentication messages, nor does it need hardware tokens as required by some previously proposed solutions. The solution is also safe against denial-of-service Attacks since no state is maintained on server side during the authentication process. We have prototyped our design both as a web browser’s plug-in and as a standalone application. A comprehensive user study was conducted. The results show that around 95% of users think the proposed solution is easy to use and manage. Further, around 79% of users have shown willingness to use the application to protect their passwords.