Protection mechanisms against phishing attacks

  • Authors:
  • Klaus Plössl;Hannes Federrath;Thomas Nowey

  • Affiliations:
  • Universität Regensburg;Universität Regensburg;Universität Regensburg

  • Venue:
  • TrustBus'05 Proceedings of the Second international conference on Trust, Privacy, and Security in Digital Business
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Approaches against Phishing can be classified into modifications of the traditional PIN/TAN-authentication on the one hand and approaches that try to reduce the probability of a scammer being successful without changing the existing PIN/TAN-method on the other hand. We present a new approach, based on challenge-response-authentication. Since our proposal does not require any new hardware on the client side, it can be implemented with little additional cost by financial institutions or other web retailers and therefore is a good compromise compared to the other approaches. A big drawback is that it doesn't protect against man-in-the-middle attacks but most of the other approaches don't either.