...
首页> 外文期刊>Advanced Science Letters >The Requirement Model for Improved OpenID Single Sign-On (SSO) Authentication to Thwart Phishing Attack
【24h】

The Requirement Model for Improved OpenID Single Sign-On (SSO) Authentication to Thwart Phishing Attack

机译:改进OpenID单点登录(SSO)认证的要求模型进行挫败网络钓鱼攻击

获取原文
获取原文并翻译 | 示例
           

摘要

The problem of password memorability among users has led to the introduction of Single Sign-On (SSO) authentication. It enables users to login using a set of username and password which then allows an access into multiple websites without the hassle of repeating the same usernames andpasswords. One of the most common SSO protocol is OpenID which is said to offer flexibility and security. Unfortunately, the existing OpenID model is prone to phishing attack whereby there is a lack of mechanism to ensure the authenticity of the OpenID provider. This scenario complicates thesituation especially when there exists tools to generate phishing attacks are easily available without requiring much technical expertise. Moreover, users awareness are claimed to be insufficient to rely on since statistics of phishing attacks are shown to be increasing. Thus, this researchattempts to propose page token as a mechanism to thwart phishing attack. This research produced and evaluated an improved requirement model that incorporates the page token as proposed mechanism. The outcomes show promising result towards the effort of thwarting phishing attacks.
机译:用户之间的密码难忘问题导致了引入单点登录(SSO)认证。它使用户能够使用一组用户名和密码登录,然后允许访问多个网站,而不会重复相同的用户名和扫描词。最常见的SSO协议之一是OpenID,据说可以提供灵活性和安全性。不幸的是,现有的OpenID模型容易出现网络钓鱼攻击,从而缺乏确保OpenID提供商的真实性的机制。这种情况使截止值复杂化,特别是当存在产生网络钓鱼攻击的工具时,很容易提供,而无需大量技术专业知识。此外,由于网络钓鱼攻击的统计数据显示,用户意识不足以依赖于,因此被认为是增加的。因此,这项研究可以将页面令牌提出作为挫败网络钓鱼攻击的机制。本研究产生并评估了一种改进的要求模型,该模型将页面令牌纳入所提出的机制。结果表明,挫败网络钓鱼攻击的努力表现出了很有希望的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号