Defeating pharming attacks at the client-side - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2011

Defeating pharming attacks at the client-side

Résumé

With the deployment of "always-connected" broadband Internet access, personal networks are a privileged target for attackers and DNS-based corruption. Pharming attacks - an enhanced version of phishing attacks - aim to steal users' credentials by redirecting them to a fraudulent login website, using DNS-based techniques that make the attack imperceptible to the end-user. In this paper, we define an advanced approach to alert the end-user in case of pharming attacks at the client-side. With a success rate over 95%, we validate a solution that can help differentiating legitimate from fraudulent login websites, based on a dual-step analysis (IP address check and webpage content comparison) performed using multiple DNS servers information

Mots clés

Fichier principal
Vignette du fichier
NSS2011-SophieGastellier-Pharming.pdf (379.75 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01303641 , version 1 (18-04-2016)

Identifiants

Citer

Sophie Gastellier-Prevost, Maryline Laurent. Defeating pharming attacks at the client-side. NSS 2011 : 5th International Conference on Network and System Security, Sep 2011, Milan, Italy. pp.33 - 40, ⟨10.1109/ICNSS.2011.6059957⟩. ⟨hal-01303641⟩
43 Consultations
298 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More