Skip navigation
  • 中文
  • English

DSpace CRIS

  • DSpace logo
  • 首頁
  • 研究成果檢索
  • 研究人員
  • 單位
  • 計畫
  • 分類瀏覽
    • 研究成果檢索
    • 研究人員
    • 單位
    • 計畫
  • 機構典藏
  • SDGs
  • 登入
  • 中文
  • English
  1. National Taiwan Ocean University Research Hub
  2. 電機資訊學院
  3. 資訊工程學系
請用此 Handle URI 來引用此文件: http://scholars.ntou.edu.tw/handle/123456789/5985
DC 欄位值語言
dc.contributor.authorHuang, C. Y.en_US
dc.contributor.authorShang-Pin Maen_US
dc.contributor.authorChen, K. T.en_US
dc.date.accessioned2020-11-19T11:43:12Z-
dc.date.available2020-11-19T11:43:12Z-
dc.date.issued2011-07-
dc.identifier.issn1084-8045-
dc.identifier.urihttp://scholars.ntou.edu.tw/handle/123456789/5985-
dc.description.abstractPhishing is now a serious threat to the security of Internet users' confidential information. Basically, an attacker (phisher) tricks people into divulging sensitive information by sending fake messages to a large number of users at random. Unsuspecting users who follow the instruction in the messages are directed to well-built spoofed web pages and asked to provide sensitive information, which the phisher then steals. Based on our observations, more than 70% of phishing activities are designed to steal users' account names and passwords. With such information, an attacker can retrieve more valuable information from the compromised accounts. Statistics published by the anti-phishing working group (APWG) show that, at the end of Q2 in 2008, the number of malicious web pages designed to steal users' passwords had increased by 258% over the same period in 2007. Therefore, protecting users from phishing attacks is extremely important. A naïve way to prevent the theft of passwords is to avoid using passwords. This raises the following question: Is it possible to authenticate a user without a preset password? In this paper, we propose a practical authentication service that eliminates the need for preset user passwords during the authentication process. By leveraging existing communication infrastructures on the Internet, i.e., the instant messaging service, it is only necessary to deploy the proposed scheme on the server side. We also show that the proposed solution can be seamlessly integrated with the OpenID service so that websites supporting OpenID benefit directly from the proposed solution. The proposed solution can be deployed incrementally, and it does not require client-side scripts, plug-ins, nor external devices. We believe that the number of phishing attacks could be reduced substantially if users were not required to provide their own passwords when accessing web pages.en_US
dc.language.isoenen_US
dc.publisherELSEVIERen_US
dc.relation.ispartofJournal of Network and Computer Applicationsen_US
dc.subjectAnti-phishingen_US
dc.subjectIdentity managementen_US
dc.subjectIn-band password deliveryen_US
dc.subjectOne-time passworden_US
dc.subjectWeb securityen_US
dc.titleUsing one-time passwords to prevent password phishing attacksen_US
dc.typejournal articleen_US
dc.identifier.doi<Go to ISI>://WOS:000291846700026-
dc.identifier.doi<Go to ISI>://WOS:000291846700026-
dc.identifier.doi10.1016/j.jnca.2011.02.004-
dc.identifier.doi<Go to ISI>://WOS:000291846700026-
dc.identifier.doi<Go to ISI>://WOS:000291846700026-
dc.identifier.url<Go to ISI>://WOS:000291846700026
dc.relation.journalvolume34en_US
dc.relation.journalissue4en_US
dc.relation.pages1292-1301en_US
item.openairetypejournal article-
item.fulltextno fulltext-
item.openairecristypehttp://purl.org/coar/resource_type/c_6501-
item.grantfulltextnone-
item.cerifentitytypePublications-
item.languageiso639-1en-
crisitem.author.deptCollege of Electrical Engineering and Computer Science-
crisitem.author.deptDepartment of Computer Science and Engineering-
crisitem.author.deptNational Taiwan Ocean University,NTOU-
crisitem.author.orcid0000-0002-3317-5750-
crisitem.author.parentorgNational Taiwan Ocean University,NTOU-
crisitem.author.parentorgCollege of Electrical Engineering and Computer Science-
顯示於:資訊工程學系
顯示文件簡單紀錄

Page view(s)

123
上周
0
上個月
0
checked on 2025/6/30

Google ScholarTM

檢查

Altmetric

Altmetric

TAIR相關文章


在 IR 系統中的文件,除了特別指名其著作權條款之外,均受到著作權保護,並且保留所有的權利。

瀏覽
  • 機構典藏
  • 研究成果檢索
  • 研究人員
  • 單位
  • 計畫
DSpace-CRIS Software Copyright © 2002-  Duraspace   4science - Extension maintained and optimized by NTU Library Logo 4SCIENCE 回饋