loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Third International Workshop on Software Engineering for Secure Systems (SESS'07: ICSE Workshops 2007)
Building Anti-Phishing Browser Plug-Ins: An Experience Report
Minneapolis, Minnesota
May 20-May 26
ISBN: 0-7695-2952-6
Thomas Raffetseder, Technical University of Vienna, Austria
Engin Kirda, Technical University of Vienna, Austria
Christopher Kruegel, Technical University of Vienna, Austria
Phishing is an online identity theft that aims to steal sensitive information such as user names, passwords, and credit card numbers. Although phishing is a simple social engineering attack, it has proven to be surprisingly effective. Hence, the number of phishing scams is continuing to grow, and the costs of the resulting damages is increasing. Researchers as well as the IT industry have identified the urgent need for anti-phishing solutions and recently, a number of solutions to mitigate phishing attacks have been proposed. Several of these approaches are browser plugins.

In 2005, we implemented a Firefox anti-phishing browser plug-in called AntiPhish. After releasing AntiPhish, we decided to port it to the Microsoft Internet Explorer (IE) browser. Supporting IE was important because a majority of Internet users are accessing the web with this browser. Our initial expectation at the beginning of the project was that porting a browser plug-in that is written for Firefox to IE could not be too difficult; after all, browser plug-ins are conceptually similar. However, creating an anti-phishing browser plug-in for the IE proved to be much more challenging than expected. In this paper, we report on our experience in implementing anti-phishing (i.e., security) browser plug-ins and summarize five lessons we learned from our undertaking.

Index Terms:
Phishing, Security, Browser Helper Objects, .NET, Internet Explorer, Firefox
Citation:
Thomas Raffetseder, Engin Kirda, Christopher Kruegel, "Building Anti-Phishing Browser Plug-Ins: An Experience Report," sess, pp.6, Third International Workshop on Software Engineering for Secure Systems (SESS'07: ICSE Workshops 2007), 2007
Usage of this product signifies your acceptance of the Terms of Use.