Combating Phishing Through Zero-Knowledge Authentication

x, 62 p. A print copy of this thesis is available through the UO Libraries. Search the library catalog for the location and call number. === Phishing is a type of Internet fraud that uses deceptive websites to trick users into revealing sensitive information. Despite the availability of numerous...

Full description

Bibliographic Details
Main Author: Knickerbocker, Paul, 1980-
Language:en_US
Published: University of Oregon 2008
Online Access:http://hdl.handle.net/1794/7891
id ndltd-uoregon.edu-oai-scholarsbank.uoregon.edu-1794-7891
record_format oai_dc
spelling ndltd-uoregon.edu-oai-scholarsbank.uoregon.edu-1794-78912018-12-20T05:47:26Z Combating Phishing Through Zero-Knowledge Authentication Knickerbocker, Paul, 1980- x, 62 p. A print copy of this thesis is available through the UO Libraries. Search the library catalog for the location and call number. Phishing is a type of Internet fraud that uses deceptive websites to trick users into revealing sensitive information. Despite the availability of numerous tools designed to detect phishing, it remains a steadily growing threat. The failure of current anti-phishing solutions is largely due to their focus on detecting phishing rather than addressing phishing's root cause: insecure web authentication. Using a combination of the zero-knowledge mechanism and two-factor authentication I present ZeKo, an authentication mechanism that is immune from phishing attacks, cryptanalysis and man-in-the-middle attacks. ZeKo takes into account the psychological behavior of users and remains secure even when the user is deceived. The proposed system not only prevents phishing attacks but also has considerable benefits over traditional authentication mechanisms, making it well suited for a wide range of applications. Advisers: Jun Li, Ginnie Lo, Reza Rejaie 2008-11-21T23:26:30Z 2008-11-21T23:26:30Z 2008-06 Thesis http://hdl.handle.net/1794/7891 en_US University of Oregon theses, Dept. of Computer and Information Science, M.S., 2008; University of Oregon
collection NDLTD
language en_US
sources NDLTD
description x, 62 p. A print copy of this thesis is available through the UO Libraries. Search the library catalog for the location and call number. === Phishing is a type of Internet fraud that uses deceptive websites to trick users into revealing sensitive information. Despite the availability of numerous tools designed to detect phishing, it remains a steadily growing threat. The failure of current anti-phishing solutions is largely due to their focus on detecting phishing rather than addressing phishing's root cause: insecure web authentication. Using a combination of the zero-knowledge mechanism and two-factor authentication I present ZeKo, an authentication mechanism that is immune from phishing attacks, cryptanalysis and man-in-the-middle attacks. ZeKo takes into account the psychological behavior of users and remains secure even when the user is deceived. The proposed system not only prevents phishing attacks but also has considerable benefits over traditional authentication mechanisms, making it well suited for a wide range of applications. === Advisers: Jun Li, Ginnie Lo, Reza Rejaie
author Knickerbocker, Paul, 1980-
spellingShingle Knickerbocker, Paul, 1980-
Combating Phishing Through Zero-Knowledge Authentication
author_facet Knickerbocker, Paul, 1980-
author_sort Knickerbocker, Paul, 1980-
title Combating Phishing Through Zero-Knowledge Authentication
title_short Combating Phishing Through Zero-Knowledge Authentication
title_full Combating Phishing Through Zero-Knowledge Authentication
title_fullStr Combating Phishing Through Zero-Knowledge Authentication
title_full_unstemmed Combating Phishing Through Zero-Knowledge Authentication
title_sort combating phishing through zero-knowledge authentication
publisher University of Oregon
publishDate 2008
url http://hdl.handle.net/1794/7891
work_keys_str_mv AT knickerbockerpaul1980 combatingphishingthroughzeroknowledgeauthentication
_version_ 1718803865486229504