English
Related papers

Related papers: Pre-hijacked accounts: An Empirical Study of Secur…

200 papers

This paper presents a practical side-channel attack that identifies the social web service account of a visitor to an attacker's website. Our attack leverages the widely adopted user-blocking mechanism, abusing its inherent property that…

Cryptography and Security · Computer Science 2018-05-15 Takuya Watanabe , Eitaro Shioji , Mitsuaki Akiyama , Keito Sasaoka , Takeshi Yagi , Tatsuya Mori

We present a large-scale characterization of attacker activity across 111 real-world enterprise organizations. We develop a novel forensic technique for distinguishing between attacker activity and benign activity in compromised enterprise…

Cryptography and Security · Computer Science 2020-07-29 Neil Shah , Grant Ho , Marco Schweighauser , M. H. Afifi , Asaf Cidon , David Wagner

In the face of large-scale automated social engineering attacks to large online services, fast detection and remediation of compromised accounts are crucial to limit the spread of new attacks and to mitigate the overall damage to users,…

Cryptography and Security · Computer Science 2018-01-29 Hassan Halawa , Matei Ripeanu , Konstantin Beznosov , Baris Coskun , Meizhu Liu

Phishing attacks are prevalent and humans are central to this online identity theft attack, which aims to steal victims' sensitive and personal information such as username, password, and online banking details. There are many anti-phishing…

Cryptography and Security · Computer Science 2018-11-26 Gitanjali Baral , Nalin Asanka Gamagedara Arachchilage

The use of passwords and the need to protect passwords are not going away. The majority of websites that require authentication continue to support password authentication. Even high-security applications such as Internet Banking portals,…

Networking and Internet Architecture · Computer Science 2020-11-13 Teik Guan Tan , Pawel Szalachowski , Jianying Zhou

Digital security technology is able to identify and prevent many threats to users accounts. However, some threats remain that, to provide reliable security, require human intervention: e.g., through users paying attention to warning…

Cryptography and Security · Computer Science 2019-01-11 Elissa M. Redmiles

Compromising social network accounts has become a profitable course of action for cybercriminals. By hijacking control of a popular media or business account, attackers can distribute their malicious messages or disseminate fake information…

Cryptography and Security · Computer Science 2015-09-14 Manuel Egele , Gianluca Stringhini , Christopher Kruegel , Giovanni Vigna

Most research into anti-phishing defence assumes that the mal-actor is attempting to harvest end-users' personally identifiable information or login credentials and, hence, focuses on detecting phishing websites. The defences for this type…

Cryptography and Security · Computer Science 2022-04-28 Trevor Wood , Vitor Basto-Fernandes , Eerke Boiten , Iryna Yevseyeva

Phishing is a type of attack in which cyber criminals tricks the victims to steal their personal and financial data. It has become an organized criminal activity. Spoofed emails claiming to be from legitimate source are crafted in a way to…

Cryptography and Security · Computer Science 2013-05-14 Ahmad Alamgir Khan

Security exploits can include cyber threats such as computer programs that can disturb the normal behavior of computer systems (viruses), unsolicited e-mail (spam), malicious software (malware), monitoring software (spyware), attempting to…

Cryptography and Security · Computer Science 2017-06-26 Nalin Asanka Gamagedara Arachchilage , Mumtaz Abdul Hameed

Phishing is the combination of social engineering and technical exploits designed to convince a victim to provide personal information, usually for the monetary gain of the attacker. Phishing has become the most popular practice among the…

Cryptography and Security · Computer Science 2011-10-04 Aanchal Jain , Vineet Richariya

Recent works showed that it is feasible to hijack resources on cloud platforms. In such hijacks, attackers can take over released resources that belong to legitimate organizations. It was proposed that adversaries could abuse these…

Networking and Internet Architecture · Computer Science 2024-03-29 Jens Frieß , Tobias Gattermayer , Nethanel Gelernter , Haya Schulmann , Michael Waidner

Phishing remains one of the most pervasive cybersecurity threats, shifting the focus from technological vulnerabilities to human cognitive and psychological factors. In coherence with the trend of studies on phishing to increasingly focus…

Cryptography and Security · Computer Science 2026-05-21 Valeria Formisano , Danilo Gentile , Gennaro Esposito Mocerino , Michela Ponticorvo , Luigi Gallo , Alessio Botta , Davide Marocco

Websites are used regularly in our day-today lives, yet research has shown that it is challenging for many users to use them securely, e.g., most prominently due to weak passwords through which they access their accounts. At the same time,…

Cryptography and Security · Computer Science 2023-02-06 Philipp Markert , Andrick Adhikari , Sanchari Das

Phishing is a type of social engineering attack with an intention to steal user data, including login credentials and credit card numbers, leading to financial losses for both organisations and individuals. It occurs when an attacker,…

Cryptography and Security · Computer Science 2020-07-02 J. Samantha Tharani , Nalin Asanka Gamagedara Arachchilage

Leaked passwords from data breaches can pose a serious threat to users if the password is reused elsewhere. With more online services getting breached today, there is still a lack of large-scale quantitative understanding of the risks of…

Cryptography and Security · Computer Science 2017-06-09 Chun Wang , Steve T. K. Jan , Hang Hu , Gang Wang

Phishing is a way of stealing people's sensitive information such as username, password and banking details by disguising as a legitimate entity (i.e. email, website). Anti-phishing education considered to be vital in strengthening "human",…

Cryptography and Security · Computer Science 2020-04-29 Matheesha Fernando , Nalin Asanka Gamagedara Arachchilage

Risk-based authentication (RBA) is used in online services to protect user accounts from unauthorized takeover. RBA commonly uses contextual features that indicate a suspicious login attempt when the characteristic attributes of the login…

Cryptography and Security · Computer Science 2024-03-19 Andre Büttner , Andreas Thue Pedersen , Stephan Wiefling , Nils Gruschka , Luigi Lo Iacono

The average user has between 90-130 online accounts, and around $3 \times 10^{11}$ passwords are in use this year. Most people are terrible at remembering "random" passwords, so they reuse or create similar passwords using a combination of…

Cryptography and Security · Computer Science 2023-10-20 Ruthu Hulikal Rooparaghunath , T. S. Harikrishnan , Debayan Gupta

Phishing is a well-known cybersecurity attack that has rapidly increased in recent years. It poses legitimate risks to businesses, government agencies, and all users due to sensitive data breaches, subsequent financial and productivity…

Cryptography and Security · Computer Science 2019-08-19 Sanchari Das , Andrew Kim , Zachary Tingle , Christena Nippert-Eng
‹ Prev 1 2 3 10 Next ›