Deakin University
Browse

File(s) under permanent embargo

Securing websites against homograph attacks

conference contribution
posted on 2018-01-01, 00:00 authored by Jemal AbawajyJemal Abawajy, A Richard, Z A Aghbari
With the globalisation of the Internet, standard frameworks such as the Internationalized Domain Name (IDN) that enable everyone to code a domain name in their native language or script has emerged. While IDN enabled coding the domain names in different languages, it has also put users of web browsers that support IDNs at risk of homograph attacks. As IDN-based homograph attacks have recently become a significant threat in content-based attacks such as phishing and other fraudulent attacks against Internet users, an approach that could automatically thwart such attacks against web browsers is important to the Internet users. To this end, we propose a new approach to mitigate the Internationalised Domain Name homograph attacks in this paper. The proposed approach is very easy to deploy in the existing browsers and requires no change in the way the end-user interact with the web-browsers. We implemented the proposed approach as an add-on to a popular web-browser and demonstrate its effectiveness against the homograph attack. Our assessment of the proposed implementation shows that the proposed solution to the IDN-based homograph attack protects web browsers with no noticeable overhead.

History

Event

European Alliance for Innovation. Conference (13th : 2017 : Niagara Falls, Ont.)

Volume

239

Series

European Alliance for Innovation Conference

Pagination

47 - 59

Publisher

Springer

Location

Niagara Falls, Ont.

Place of publication

Cham, Switzerland

Start date

2017-10-22

End date

2017-10-25

ISSN

1867-8211

ISBN-13

9783319788159

Language

eng

Publication classification

E1 Full written paper - refereed

Copyright notice

2018, ICST Institute for Computer Sciences, Social Informatics and Telecommunications Engineering

Editor/Contributor(s)

X Lin, A Ghorbani, K Ren, S Zhu, A Zhang

Title of proceedings

SecureComm 2017 : Proceedings of the 13th EAI International Conference on Security and Privacy Communication Networks