CRFeb 24, 2015

Personalized Security Indicators to Detect Application Phishing Attacks in Mobile Platforms

arXiv:1502.06824v136 citations
Originality Incremental advance
AI Analysis

This addresses mobile application phishing for users, showing that personalized indicators can be effective despite previous skepticism, though it is incremental as it adapts an existing concept to a new context.

The paper tackles the problem of phishing attacks in mobile applications by evaluating personalized security indicators, finding that users with these indicators detected phishing attacks significantly more often than those without, with all non-users entering credentials to phishing apps.

Phishing in mobile applications is a relevant threat with successful attacks reported in the wild. In such attacks, malicious mobile applications masquerade as legitimate ones to steal user credentials. In this paper we categorize application phishing attacks in mobile platforms and possible countermeasures. We show that personalized security indicators can help users to detect phishing attacks and have very little deployment cost. Personalized security indicators, however, rely on the user alertness to detect phishing attacks. Previous work in the context of website phishing has shown that users tend to ignore the absence of security indicators and fall victim of the attacker. Consequently, the research community has deemed personalized security indicators as an ineffective phishing detection mechanism. We evaluate personalized security indicators as a phishing detection solution in the context of mobile applications. We conducted a large-scale user study where a significant amount of participants that used personalized security indicators were able to detect phishing. All participants that did not use indicators could not detect the attack and entered their credentials to a phishing application. We found the difference in the attack detection ratio to be statistically significant. Personalized security indicators can, therefore, help phishing detection in mobile applications and their reputation as an anti-phishing mechanism should be reconsidered. We also propose a novel protocol to setup personalized security indicators under a strong adversarial model and provide details on its performance and usability.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes