A dual approach to detect pharming attacks at the client-side

Sophie Gastellier-Prevost, Gustavo Gonzalez Granadillo, Maryline Laurent

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Pharming attacks - a sophisticated version of phishing attacks - aim to steal users' credentials by redirecting them to a fraudulent website using DNS-based techniques. Pharming attacks can be performed at the client-side or into the Internet, using complex and well designed techniques that make the attack often imperceptible to the user. With the deployment of broadband connections for Internet access, personal networks are a privileged target for attackers. In this paper, we propose a dual approach to provide an anti-pharming protection integrated into the client's browser. Our approach combines both an IP address check as well as a webpage content analysis, using the information provided by multiple DNS servers. We present first experimental results and we discuss about future works and limitations of our approach.

Original languageEnglish
Title of host publication2011 4th IFIP International Conference on New Technologies, Mobility and Security, NTMS 2011 - Proceedings
DOIs
Publication statusPublished - 25 Mar 2011
Externally publishedYes
Event4th IFIP International Conference on New Technologies, Mobility and Security, NTMS 2011 - Paris, France
Duration: 7 Feb 201110 Feb 2011

Publication series

Name2011 4th IFIP International Conference on New Technologies, Mobility and Security, NTMS 2011 - Proceedings

Conference

Conference4th IFIP International Conference on New Technologies, Mobility and Security, NTMS 2011
Country/TerritoryFrance
CityParis
Period7/02/1110/02/11

Keywords

  • Attack
  • Client-side
  • DNS
  • Pharming
  • Phishing
  • Security
  • Webpage

Fingerprint

Dive into the research topics of 'A dual approach to detect pharming attacks at the client-side'. Together they form a unique fingerprint.

Cite this