A zero knowledge password proof mutual authentication technique against real-time phishing attacks

  • Authors:
  • Mohsen Sharifi;Alireza Saberi;Mojtaba Vahidi;Mohammad Zorufi

  • Affiliations:
  • Computer Engineering Department, Iran University of Science and Technology;Computer Engineering Department, Iran University of Science and Technology;Computer Engineering Department, Iran University of Science and Technology;Computer Engineering Department, Iran University of Science and Technology

  • Venue:
  • ICISS'07 Proceedings of the 3rd international conference on Information systems security
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Phishing attack is a kind of identity theft trying to steal confidential data. Existing approaches against phishing attacks cannot prevent real-time phishing attacks. This paper proposes an Anti-Phishing Authentication (APA) technique to detect and prevent real-time phishing attacks. It uses 2-way authentication and zero-knowledge password proof. Users are recommended to customize their user interfaces and thus defend themselves against spoofing. The proposed technique assumes the preexistence of a shared secret key between any two communicating partners, and ignores the existence of any malware at client sides.