The Experts below are selected from a list of 4695 Experts worldwide ranked by ideXlab platform
Zhiting Ling - One of the best experts on this subject based on the ideXlab platform.
-
CSPS (3) - An Analysis of a New Detection Method for Spear Phishing Attack.
Lecture Notes in Electrical Engineering, 2019Co-Authors: Yaping Chi, Zhiting LingAbstract:A new method to detect credential spear Phishing Attack for the network is introduced in the conference of 26th USENIX Security Symposium. First, on the basis of the researching for the processes and the principles of spear Phishing Attack, and the overall structure of its detector, the Directed Anomaly Scoring technology is analyzed in the paper. Second, the selections of scalars in subdetectors are defined. Third, the spear Phishing Attack detection method of detector and the methods of traditional detection are compared and analyzed. And then, the obvious advantages of the detector are discussed. The prospection of the spear Phishing Attack detection development is also given at the end of the paper.
-
an analysis of a new detection method for spear Phishing Attack
International Conference on Communications, 2018Co-Authors: Yaping Chi, Zhiting LingAbstract:A new method to detect credential spear Phishing Attack for the network is introduced in the conference of 26th USENIX Security Symposium. First, on the basis of the researching for the processes and the principles of spear Phishing Attack, and the overall structure of its detector, the Directed Anomaly Scoring technology is analyzed in the paper. Second, the selections of scalars in subdetectors are defined. Third, the spear Phishing Attack detection method of detector and the methods of traditional detection are compared and analyzed. And then, the obvious advantages of the detector are discussed. The prospection of the spear Phishing Attack detection development is also given at the end of the paper.
S Swamynathan - One of the best experts on this subject based on the ideXlab platform.
-
a robust defense mechanism to prevent Phishing Attack using parse tree validation
International Conference on Advanced Computing, 2011Co-Authors: V Shanmughaneethi, Regan Abraham, S SwamynathanAbstract:In modern era, Web-based applications and services have changed the landscape of information delivery and exchange in today's corporate, government and educational arenas. An increase in the usage of web applications is directly related to the number of security threats for them. The threats leveraged through vulnerabilities, that leads to creating an Attack in web applications and it will be create severe damage in online transactions. Among the various types of the website Attack, Phishing Attack is the most common and well-known type in web application. Phishing is a cyber crime activity performed to acquire user's sensitive information such as passwords and credit card, social security, and bank account details by masquerading as a trustworthy entity in an electronic communication. This kind of threat is famous in online payment web sites, online auction and online backing web sites. In this paper we have proposed a novel approach to detect the Phishing web sites by passing the user requested website address to the Google Application Programming Interface (API) to intercepting most relevance URLs (Uniform Resource Locater). The intercepted URLs are used to constructing a parse tree with the root node of requested URL. The constructed parse tree will be employed to validate the requested web site address. Identification of the Phishing web site is implemented through independent web services. Our approach in a web application is independent module and it doesn't demand any change in application.
Nur Haryani Zakaria - One of the best experts on this subject based on the ideXlab platform.
-
An Evaluation of Page Token in OpenID Single Sign on (SSO) to Thwart Phishing Attack
Journal of Telecommunication Electronic and Computer Engineering, 2018Co-Authors: Nur Haryani Zakaria, Norliza Katuk, Mohd Faizal Zainul, Hatim Mohammad Tahir, Mohd Nizam OmarAbstract:Single Sign-on (SSO) was introduced to overcome the issue of password memorability among users as researches have shown that users struggle to cope with too many sets of password as number of account increases. This is due to SSO relies on the usage of single authentication that allows users to access to multiple websites or services. As much as it has managed to solve the memorability issue to certain extend, users were found to have skeptical in its adoption due to security concerns. Among common issues of SSO is that it is prone to several Attacks like spam, link manipulation, session hacking and particularly Phishing. Despite of many efforts been placed to overcome Phishing Attack with regards to SSO, the effectiveness of the proposed solutions are yet to be proven by conducting extensive evaluation. Thus, this study intends to conduct an evaluation on a particular solution of Phishing Attack call page token. Page token was proposed recently which was claimed to be able to mitigate the issue of Phishing Attack with regards to SSO application. The evaluation involved a control laboratory experiment with participants being recruited to experience the usage of page token as a protection mechanism against Phishing Attack. The results showed are promising along with several suggestions given for further enhancement.
-
The requirement model for improved openID single Sign-On (SSO) authentication to thwart Phishing Attack
Advanced Science Letters, 2017Co-Authors: Nur Haryani Zakaria, Norliza Katuk, Hatim Mohamad Tahir, Nadia Hasidah Mat Nayan, Abubakar MohammedAbstract:The problem of password memorability among users has led to the introduction of Single Sign-On (SSO) authentication. It enables users to login using a set of username and password which then allows an access into multiple websites without the hassle of repeating the same usernames and passwords. One of the most common SSO protocol is OpenID which is said to offer flexibility and security. Unfortunately, the existing OpenID model is prone to Phishing Attack whereby there is a lack of mechanism to ensure the authenticity of the OpenID provider. This scenario complicates the situation especially when there exists tools to generate Phishing Attacks are easily available without requiring much technical expertise. Moreover, users awareness are claimed to be insufficient to rely on since statistics of Phishing Attacks are shown to be increasing. Thus, this research attempts to propose page token as a mechanism to thwart Phishing Attack. This research produced and evaluated an improved requirement model that incorporates the page token as proposed mechanism. The outcomes show promising result towards the effort of thwarting Phishing Attacks.
-
A Page Token Prototype of OpenID Single Sign-On (SSO) to Thwart Phishing Attack
Journal of Telecommunication Electronic and Computer Engineering, 2016Co-Authors: Nur Haryani Zakaria, Wan Mohd Yusoff Wan Yaacob, Norliza Katuk, Hatim Mohamad Tahir, Mohd Nizam OmarAbstract:Single Sign-on (SSO) authentication was introduced to overcome the problem of password memorability issue by enabling the users to login once using a set of username and password that allows an access into multiple websites. Among several SSO protocol, OpenID is said to offer flexibility and security. Unfortunately, the existing OpenID model is prone to Phishing Attack due to lack of countermeasures to ensure authenticity of OpenID provider. In view of the proliferation of Phishing Attack that exposed users to fraud website, information theft and unauthorized disclosure, this study attempts to identify and propose a suitable countermeasure in order to thwart Phishing Attack in OpenID environment. Therefore, this study intends to develop a prototype that implements Page Token in order to mitigate Phishing Attack. The findings revealed that the Page Token is possible to minimize the potential risk of Phishing Attack.
Mohd Nizam Omar - One of the best experts on this subject based on the ideXlab platform.
-
An Evaluation of Page Token in OpenID Single Sign on (SSO) to Thwart Phishing Attack
Journal of Telecommunication Electronic and Computer Engineering, 2018Co-Authors: Nur Haryani Zakaria, Norliza Katuk, Mohd Faizal Zainul, Hatim Mohammad Tahir, Mohd Nizam OmarAbstract:Single Sign-on (SSO) was introduced to overcome the issue of password memorability among users as researches have shown that users struggle to cope with too many sets of password as number of account increases. This is due to SSO relies on the usage of single authentication that allows users to access to multiple websites or services. As much as it has managed to solve the memorability issue to certain extend, users were found to have skeptical in its adoption due to security concerns. Among common issues of SSO is that it is prone to several Attacks like spam, link manipulation, session hacking and particularly Phishing. Despite of many efforts been placed to overcome Phishing Attack with regards to SSO, the effectiveness of the proposed solutions are yet to be proven by conducting extensive evaluation. Thus, this study intends to conduct an evaluation on a particular solution of Phishing Attack call page token. Page token was proposed recently which was claimed to be able to mitigate the issue of Phishing Attack with regards to SSO application. The evaluation involved a control laboratory experiment with participants being recruited to experience the usage of page token as a protection mechanism against Phishing Attack. The results showed are promising along with several suggestions given for further enhancement.
-
A Page Token Prototype of OpenID Single Sign-On (SSO) to Thwart Phishing Attack
Journal of Telecommunication Electronic and Computer Engineering, 2016Co-Authors: Nur Haryani Zakaria, Wan Mohd Yusoff Wan Yaacob, Norliza Katuk, Hatim Mohamad Tahir, Mohd Nizam OmarAbstract:Single Sign-on (SSO) authentication was introduced to overcome the problem of password memorability issue by enabling the users to login once using a set of username and password that allows an access into multiple websites. Among several SSO protocol, OpenID is said to offer flexibility and security. Unfortunately, the existing OpenID model is prone to Phishing Attack due to lack of countermeasures to ensure authenticity of OpenID provider. In view of the proliferation of Phishing Attack that exposed users to fraud website, information theft and unauthorized disclosure, this study attempts to identify and propose a suitable countermeasure in order to thwart Phishing Attack in OpenID environment. Therefore, this study intends to develop a prototype that implements Page Token in order to mitigate Phishing Attack. The findings revealed that the Page Token is possible to minimize the potential risk of Phishing Attack.
Norliza Katuk - One of the best experts on this subject based on the ideXlab platform.
-
An Evaluation of Page Token in OpenID Single Sign on (SSO) to Thwart Phishing Attack
Journal of Telecommunication Electronic and Computer Engineering, 2018Co-Authors: Nur Haryani Zakaria, Norliza Katuk, Mohd Faizal Zainul, Hatim Mohammad Tahir, Mohd Nizam OmarAbstract:Single Sign-on (SSO) was introduced to overcome the issue of password memorability among users as researches have shown that users struggle to cope with too many sets of password as number of account increases. This is due to SSO relies on the usage of single authentication that allows users to access to multiple websites or services. As much as it has managed to solve the memorability issue to certain extend, users were found to have skeptical in its adoption due to security concerns. Among common issues of SSO is that it is prone to several Attacks like spam, link manipulation, session hacking and particularly Phishing. Despite of many efforts been placed to overcome Phishing Attack with regards to SSO, the effectiveness of the proposed solutions are yet to be proven by conducting extensive evaluation. Thus, this study intends to conduct an evaluation on a particular solution of Phishing Attack call page token. Page token was proposed recently which was claimed to be able to mitigate the issue of Phishing Attack with regards to SSO application. The evaluation involved a control laboratory experiment with participants being recruited to experience the usage of page token as a protection mechanism against Phishing Attack. The results showed are promising along with several suggestions given for further enhancement.
-
The requirement model for improved openID single Sign-On (SSO) authentication to thwart Phishing Attack
Advanced Science Letters, 2017Co-Authors: Nur Haryani Zakaria, Norliza Katuk, Hatim Mohamad Tahir, Nadia Hasidah Mat Nayan, Abubakar MohammedAbstract:The problem of password memorability among users has led to the introduction of Single Sign-On (SSO) authentication. It enables users to login using a set of username and password which then allows an access into multiple websites without the hassle of repeating the same usernames and passwords. One of the most common SSO protocol is OpenID which is said to offer flexibility and security. Unfortunately, the existing OpenID model is prone to Phishing Attack whereby there is a lack of mechanism to ensure the authenticity of the OpenID provider. This scenario complicates the situation especially when there exists tools to generate Phishing Attacks are easily available without requiring much technical expertise. Moreover, users awareness are claimed to be insufficient to rely on since statistics of Phishing Attacks are shown to be increasing. Thus, this research attempts to propose page token as a mechanism to thwart Phishing Attack. This research produced and evaluated an improved requirement model that incorporates the page token as proposed mechanism. The outcomes show promising result towards the effort of thwarting Phishing Attacks.
-
A Page Token Prototype of OpenID Single Sign-On (SSO) to Thwart Phishing Attack
Journal of Telecommunication Electronic and Computer Engineering, 2016Co-Authors: Nur Haryani Zakaria, Wan Mohd Yusoff Wan Yaacob, Norliza Katuk, Hatim Mohamad Tahir, Mohd Nizam OmarAbstract:Single Sign-on (SSO) authentication was introduced to overcome the problem of password memorability issue by enabling the users to login once using a set of username and password that allows an access into multiple websites. Among several SSO protocol, OpenID is said to offer flexibility and security. Unfortunately, the existing OpenID model is prone to Phishing Attack due to lack of countermeasures to ensure authenticity of OpenID provider. In view of the proliferation of Phishing Attack that exposed users to fraud website, information theft and unauthorized disclosure, this study attempts to identify and propose a suitable countermeasure in order to thwart Phishing Attack in OpenID environment. Therefore, this study intends to develop a prototype that implements Page Token in order to mitigate Phishing Attack. The findings revealed that the Page Token is possible to minimize the potential risk of Phishing Attack.