Featured Research

from universities, journals, and other organizations

Computer Engineers Create New System To Curb Phishing Fraud

Date:
September 3, 2006
Source:
Carnegie Mellon University
Summary:
Carnegie Mellon University Cylab researchers have developed a new anti-phishing tool to protect users from online transactions at fraudulent Web sites.

Carnegie Mellon University CyLab researchers have developed a new anti-phishing tool to protect users from online transactions at fraudulent Web sites.

Related Articles


A research team led by Electrical and Computer Engineering Professor Adrian Perrig has created the Phoolproof Phishing Prevention system that protects users against all network-based attacks, even when they make mistakes. The innovative security system provides strong mutual authentication between the Web server and the user by leveraging a mobile device, such as the user's cell phone or PDA.

The system is also designed to be easy for businesses to implement. Perrig, along with engineering Ph.D. student assistants Bryan Parno and Cynthia Kuo, has developed an anti-phishing system that makes the user's cell phone an active participant in the authentication process to securely communicate with a particular Internet site.

"Essentially, our research indicates that Internet users do not always make correct security decisions, so our new system helps them make the right decision, and protects them even if they manage to make a wrong decision," Perrig said. "Our new anti-phishing system, which operates with the standard secure Web protocol, ensures that the user accesses the Web site they intend to visit, instead of a phishing site posing as a legitimate business. The mobile device acts like an electronic assistant, storing a secure bookmark and a cryptographic key for each of the user's online accounts."

Phoolproof Phishing Prevention essentially provides a secure electronic key ring that the user can access while making online transactions, according to Parno. These special keys are more secure than one-time passwords because the user can't give them away. So, phishers can't access the user's accounts, even if they obtain other information about the user, researchers said.

Since the user's cell phone performs cryptographic operations without revealing the secret key to the user's computer, the system also defends against keyloggers and other malicious software on the user's computer. Even if the user loses the cell phone, the keys remain secure.

Driving the need for this new tool is escalating consumer worries over online fraud -- a major barrier for a banking industry seeking to push consumers to do more of their banking online. More than 5 percent of Internet users say they have stopped banking online because of security concerns, up from 1 percent a year ago, according to industry reports.

Complicating the concern for more secure financial sites is a looming deadline for new security guidelines from the Federal Financial Institutions Examination Council (FFIEC), a group of government agencies that sets standards for financial institutions. Last year, the FFIEC set a Dec. 31 deadline for banks to add online security measures beyond just a user name and password. Failure to meet that deadline could result in fines, the FFIEC said.

Additional details about Phoolproof Phishing Prevention can be found at sparrow.ece.cmu.edu/~parno/phishing/.

About Carnegie Mellon CyLab: Carnegie Mellon CyLab is a university-wide, multidisciplinary initiative involving more than 200 faculty, students and staff. Carnegie Mellon CyLab is a bold and visionary effort aimed at creating a public-private partnership to develop new technologies for measurable, available, secure, trustworthy and sustainable computing and communication systems, and to educate individuals at all levels.


Story Source:

The above story is based on materials provided by Carnegie Mellon University. Note: Materials may be edited for content and length.


Cite This Page:

Carnegie Mellon University. "Computer Engineers Create New System To Curb Phishing Fraud." ScienceDaily. ScienceDaily, 3 September 2006. <www.sciencedaily.com/releases/2006/09/060901161757.htm>.
Carnegie Mellon University. (2006, September 3). Computer Engineers Create New System To Curb Phishing Fraud. ScienceDaily. Retrieved March 27, 2015 from www.sciencedaily.com/releases/2006/09/060901161757.htm
Carnegie Mellon University. "Computer Engineers Create New System To Curb Phishing Fraud." ScienceDaily. www.sciencedaily.com/releases/2006/09/060901161757.htm (accessed March 27, 2015).

Share This


More From ScienceDaily



More Computers & Math News

Friday, March 27, 2015

Featured Research

from universities, journals, and other organizations


Featured Videos

from AP, Reuters, AFP, and other news services

AAA: Distracted Driving a Serious Teen Problem

AAA: Distracted Driving a Serious Teen Problem

AP (Mar. 25, 2015) While distracted driving is not a new problem for teens, new research from the AAA Foundation for Traffic Safety says it&apos;s much more serious than previously thought. (March 25) Video provided by AP
Powered by NewsLook.com
Amazon Complains U.S. Is Too Slow To Regulate Drones

Amazon Complains U.S. Is Too Slow To Regulate Drones

Newsy (Mar. 25, 2015) Days after getting approval to test certain commercial drones, Amazon says the Federal Aviation Administration is dragging its feet on the matter. Video provided by Newsy
Powered by NewsLook.com
Facebook Ups Its Messenger Game

Facebook Ups Its Messenger Game

Reuters - Business Video Online (Mar. 25, 2015) Facebook is taking another step towards making its users into consumers for its growing base of advertisers, by expanding its messenger service features. Bobbi Rebell reports. Video provided by Reuters
Powered by NewsLook.com
Smartphone Use Changing Our Brain and Thumb Interaction, Say Researchers

Smartphone Use Changing Our Brain and Thumb Interaction, Say Researchers

Reuters - Innovations Video Online (Mar. 25, 2015) European researchers say our smartphone use offers scientists an ideal testing ground for human brain plasticity. Dr Ako Ghosh&apos;s team discovered that the brains and thumbs of smartphone users interact differently from those who use old-fashioned handsets. Jim Drury went to meet him. Video provided by Reuters
Powered by NewsLook.com

Search ScienceDaily

Number of stories in archives: 140,361

Find with keyword(s):
Enter a keyword or phrase to search ScienceDaily for related topics and research stories.

Save/Print:
Share:

Breaking News:

Strange & Offbeat Stories


Space & Time

Matter & Energy

Computers & Math

In Other News

... from NewsDaily.com

Science News

Health News

Environment News

Technology News



Save/Print:
Share:

Free Subscriptions


Get the latest science news with ScienceDaily's free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

Get Social & Mobile


Keep up to date with the latest news from ScienceDaily via social networks and mobile apps:

Have Feedback?


Tell us what you think of ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?
Mobile: iPhone Android Web
Follow: Facebook Twitter Google+
Subscribe: RSS Feeds Email Newsletters
Latest Headlines Health & Medicine Mind & Brain Space & Time Matter & Energy Computers & Math Plants & Animals Earth & Climate Fossils & Ruins