Geo-location based QR-Code authentication scheme to defeat active real-time phishing attack

  • Authors:
  • Seung-Hyun Kim;Daeseon Choi;Seung-Hun Jin;Sung-Hoon Lee

  • Affiliations:
  • ETRI, Daejeon, South Korea;ETRI, Daejeon, South Korea;ETRI, Daejeon, South Korea;ETRI/UST, Daejeon, South Korea

  • Venue:
  • Proceedings of the 2013 ACM workshop on Digital identity management
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Internet phishing attacks have been evolving along with the growth of online transactions on the Internet. MITM(Man-In-The-Middle) phishing is an attack that manipulates authentication and transaction information when an attacker is located in between a web server and a user. The possibility of this sort of phishing attack has been posed for a long time, but the menace was mostly ignored. Since Bruce Schneier introduced the concept of emasculating two-factor authentication in 2005, Leung and Jakobsson proposed Control Relay-MITM and doppelganger phishing attacks, respectively. In this paper, we introduce ART(Active Real-Time) MITM phishing attack as an enhanced phishing attack against above ones. While providing same UX(User eXperience) of real web server to a user, ART-MITM makes all security solutions that are installed on the user's computer useless and runs automated attack processes. To defeat against ART-MITM phishing attack, we propose a geo-location based QR-code authentication scheme using mobile phone. The proposed scheme provides convenience, mobility, and security for the user; as a result, the scheme can be seen as a realistic solution to such enhanced phishing attacks.