Defeating pharming attacks at the client-side

Sophie Gastellier-Prevost, Maryline Laurent

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

With the deployment of always-connected broadband Internet access, personal networks are a privileged target for attackers and DNS-based corruption. Pharming attacks - an enhanced version of phishing attacks - aim to steal users' credentials by redirecting them to a fraudulent login website, using DNS-based techniques that make the attack imperceptible to the end-user. In this paper, we define an advanced approach to alert the end-user in case of pharming attacks at the client-side. With a success rate over 95%, we validate a solution that can help differentiating legitimate from fraudulent login websites, based on a dual-step analysis (IP address check and webpage content comparison) performed using multiple DNS servers information.

Original languageEnglish
Title of host publicationProceedings - 2011 5th International Conference on Network and System Security, NSS 2011
Pages33-40
Number of pages8
DOIs
Publication statusPublished - 17 Nov 2011
Externally publishedYes
Event2011 5th International Conference on Network and System Security, NSS 2011 - Milan, Italy
Duration: 6 Sept 20118 Sept 2011

Publication series

NameProceedings - 2011 5th International Conference on Network and System Security, NSS 2011

Conference

Conference2011 5th International Conference on Network and System Security, NSS 2011
Country/TerritoryItaly
CityMilan
Period6/09/118/09/11

Fingerprint

Dive into the research topics of 'Defeating pharming attacks at the client-side'. Together they form a unique fingerprint.

Cite this