中文
相关论文

相关论文: Lazy Gatekeepers: A Large-Scale Study on SPF Confi…

200 篇论文

Spam domains are sources of unsolicited mails and one of the primary vehicles for fraud and malicious activities such as phishing campaigns or malware distribution. Spam domain detection is a race: as soon as the spam mails are sent, taking…

密码学与安全 · 计算机科学 2022-05-05 Simon Fernandez , Maciej Korczyński , Andrzej Duda

The critical role played by email has led to a range of extension protocols (e.g., SPF, DKIM, DMARC) designed to protect against the spoofing of email sender domains. These protocols are complex as is, but are further complicated by…

密码学与安全 · 计算机科学 2023-04-21 Enze Liu , Gautam Akiwate , Mattijs Jonker , Ariana Mirian , Grant Ho , Geoffrey M. Voelker , Stefan Savage

Email spoofing is a critical step of phishing, where the attacker impersonates someone the victim knows or trusts. In this paper, we conduct a qualitative study to explore why email spoofing is still possible after years of efforts to…

密码学与安全 · 计算机科学 2018-02-08 Hang Hu , Peng Peng , Gang Wang

The SSH protocol is commonly used to access remote systems on the Internet, as it provides an encrypted and authenticated channel for communication. If upon establishing a new connection, the presented server key is unknown to the client,…

密码学与安全 · 计算机科学 2022-11-24 Sebastian Neef , Nils Wisiol

The email system is the central battleground against phishing and social engineering attacks, and yet email providers still face key challenges to authenticate incoming emails. As a result, attackers can apply spoofing techniques to…

密码学与安全 · 计算机科学 2018-01-04 Hang Hu , Gang Wang

Emails are used every day for communication, and many countries and organisations mostly use email for official communications. It is highly valued and recognised for confidential conversations and transactions in day-to-day business. The…

密码学与安全 · 计算机科学 2023-12-08 Peace Nmachi Wosah

The security evaluation for Mail Distribution Systems focuses on certification and reliability of sensitive data between mail servers. The need to certify the information conveyed is a result of known weaknesses in the simple mail transfer…

密码学与安全 · 计算机科学 2014-11-18 Antonis S. Rizopoulos , Dimitrios N. Kallergis , George N. Prezerakos

Short Message Service (SMS) is a popular channel for online service providers to verify accounts and authenticate users registered to a particular service. Specialized applications, called Public SMS Gateways (PSGs), offer free Disposable…

密码学与安全 · 计算机科学 2024-08-27 José Miguel Moreno , Srdjan Matic , Narseo Vallina-Rodriguez , Juan Tapiador

Password-based authentication faces various security and usability issues. Password managers help alleviate some of these issues by enabling users to manage their passwords effectively. However, malicious client-side scripts and browser…

密码学与安全 · 计算机科学 2024-02-12 Anuj Gautam , Tarun Kumar Yadav , Kent Seamons , Scott Ruoti

Researchers have extensively explored how password creation policies influence the security and usability of user-chosen passwords, producing evidence-based policy guidelines. However, for web authentication to improve in practice, websites…

密码学与安全 · 计算机科学 2023-09-08 Suood Alroomi , Frank Li

Domain Name System (DNS) domains became Internet-level identifiers for entities (like companies, organizations, or individuals) hosting services and sharing resources over the Internet. Domains can specify a set of security policies (such…

密码学与安全 · 计算机科学 2018-04-13 Gaurav Varshney , Pawel Szalachowski

The widespread usage of password authentication in online websites leads to an ever-increasing concern, especially when considering the possibility for an attacker to recover the user password by leveraging the loopholes in the password…

密码学与安全 · 计算机科学 2018-04-25 Simone Raponi , Roberto Di Pietro

Forward Secrecy (FS) is a security property in key-exchange algorithms which guarantees that a compromise in the secrecy of a long-term private-key does not compromise the secrecy of past session keys. With a growing awareness of long-term…

密码学与安全 · 计算机科学 2019-07-02 Eman Salem Alashwali , Pawel Szalachowski , Andrew Martin

This paper concerns the problem of the absence of ingress filtering at the network edge, one of the main causes of important network security issues. Numerous network operators do not deploy the best current practice - Source Address…

网络与互联网体系结构 · 计算机科学 2020-03-31 Maciej Korczyński , Yevheniya Nosyk , Qasim Lone , Marcin Skwarek , Baptiste Jonglez , Andrzej Duda

Phishing is one of the most prevalent and expensive types of cybercrime faced by organizations and individuals worldwide. Most prior research has focused on various technical features and traditional representations of text to characterize…

密码学与安全 · 计算机科学 2024-08-20 Tarini Saka , Rachiyta Jain , Kami Vaniea , Nadin Kökciyan

As a fundamental communicative service, email is playing an important role in both individual and corporate communications, which also makes it one of the most frequently attack vectors. An email's authenticity is based on an authentication…

密码学与安全 · 计算机科学 2022-04-15 Kaiwen Shen , Chuhan Wang , Minglei Guo , Xiaofeng Zheng , Chaoyi Lu , Baojun Liu , Yuxuan Zhao , Shuang Hao , Haixin Duan , Qingfeng Pan , Min Yang

Misconfigurations and outdated software are a major cause of compromised websites and data leaks. Past research has proposed and evaluated sending automated security notifications to the operators of misconfigured websites, but encountered…

We perform a passive measurement study investigating how a Protective DNS service might perform in a Research & Education Network serving hundreds of member institutions. Utilizing freely-available DNS blocklists consisting of domain names…

密码学与安全 · 计算机科学 2025-10-30 David Plonka , Branden Palacio , Debbie Perouli

Phishing continues to pose a significant cybersecurity threat. While blocklists currently serve as a primary defense, due to their reactive, passive nature, these delayed responses leave phishing websites operational long enough to harm…

密码学与安全 · 计算机科学 2025-04-18 Kyungchan Lim , Raffaele Sommese , Mattis Jonker , Ricky Mok , kc claffy , Doowon Kim

Spear phishing is a deceptive attack that uses social engineering to obtain confidential information through targeted victimization. It is distinguished by its use of social cues and personalized information to target specific victims.…

密码学与安全 · 计算机科学 2020-07-09 Ploy Unchit , Sanchari Das , Andrew Kim , L. Jean Camp
‹ 上一页 1 2 3 10 下一页 ›