Publication | Closed Access
Web wallet
161
Citations
12
References
2006
Year
Unknown Venue
Internet SecurityEngineeringUsable SecurityInformation SecurityPhishingWeb SecurityIdentity-based SecurityWeb WalletWeb Wallet PrototypeNew Anti-phishing Solution
The Web Wallet is a new anti‑phishing solution that protects users by detecting phishing sites and guiding them to safe destinations. It operates as a browser sidebar that monitors where users intend to submit sensitive data, compares the target site to the intended destination, and, if mismatched, offers a safe alternative while embedding security questions into the workflow. A user study showed the Web Wallet reduced spoofing from 63 % to 7 % and prevented all attacks when used, with most participants adopting it, though attackers could spoof the interface and users still sometimes typed directly into forms.
We introduce a new anti-phishing solution, the Web Wallet. The Web Wallet is a browser sidebar which users can use to submit their sensitive information online. It detects phishing attacks by determining where users intend to submit their information and suggests an alternative safe path to their intended site if the current site does not match it. It integrates security questions into the user's workflow so that its protection cannot be ignored by the user. We conducted a user study on the Web Wallet prototype and found that the Web Wallet is a promising approach. In the study, it significantly decreased the spoof rate of typical phishing attacks from 63% to 7%, and it effectively prevented all phishing attacks as long as it was used. A majority of the subjects successfully learned to depend on the Web Wallet to submit their login information. However, the study also found that spoofing the Web Wallet interface itself was an effective attack. Moreover, it was not easy to completely stop all subjects from typing sensitive information directly into web forms.
| Year | Citations | |
|---|---|---|
Page 1
Page 1