TY - GEN
T1 - Alice, what did you do last time? Fighting phishing using past activity tests
AU - Nikiforakis, Nikos
AU - Makridakis, Andreas
AU - Athanasopoulos, Elias
AU - Markatos, Evangelos P.
PY - 2009
Y1 - 2009
N2 - Phishing attacks are one of the most crucial modern security threats in the current World Wide Web. An adversary may clone a legitimate Web site and lure a user to submit her credentials to the malicious construct. The adversary may then use the stolen credentials to the authentic site. In this paper we present a novel idea to fight phishing using Past Activity Tests (PACTs). In a nutshell, PACTs take advantage of the fact that the user has accessed at least once her account in the past, contrary to the phisher who accesses the user's account for the first time. Thus, a user can answer a question relative to her past activity, but the attacker can not.
AB - Phishing attacks are one of the most crucial modern security threats in the current World Wide Web. An adversary may clone a legitimate Web site and lure a user to submit her credentials to the malicious construct. The adversary may then use the stolen credentials to the authentic site. In this paper we present a novel idea to fight phishing using Past Activity Tests (PACTs). In a nutshell, PACTs take advantage of the fact that the user has accessed at least once her account in the past, contrary to the phisher who accesses the user's account for the first time. Thus, a user can answer a question relative to her past activity, but the attacker can not.
UR - https://www.scopus.com/pages/publications/84884994690
U2 - 10.1007/978-0-387-85555-4_7
DO - 10.1007/978-0-387-85555-4_7
M3 - Conference contribution
AN - SCOPUS:84884994690
SN - 9780387855547
T3 - Lecture Notes in Electrical Engineering
SP - 107
EP - 117
BT - Proceedings of the 3rd European Conference on Computer Network Defense
T2 - 3rd European Conference on Computer Network Defense, EC2ND 2007
Y2 - 4 October 2007 through 5 October 2007
ER -