Phishing defense against IDN address spoofing attacks

  • Authors:
  • Viktor Krammer

  • Affiliations:
  • E-Commerce Competence Center and Vienna University of Technology, Vienna, Austria

  • Venue:
  • Proceedings of the 2006 International Conference on Privacy, Security and Trust: Bridge the Gap Between PST Technologies and Business Services
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Address spoofing is a common trick used in phishing scams to confuse unsuspecting users about a Web site's real origin. With the introduction of Unicode characters into domain names, also known as Internationalized Domain Names (IDN), the risk has significantly increased even for the most cautious users. The author explores the various types of address spoofing attacks focusing on IDN, and presents a novel client-side Web browser plug-in Quero which implements several techniques---including highlighting---to protect the user against visually undistinguishable address manipulations.