380 likes | 403 Views
Anti-Phishing Technology. Chokepoints and Countermeasures. Aaron Emigh Radix Labs aaron@radixlabs.com. A Typical Phishing Email. Phishing Information Flow. Step 1: Phish Delivery. Authentication. Reducing False Positives. . Image Recognition. Simple idea: recognize logos.
E N D
Anti-Phishing Technology Chokepoints and Countermeasures Aaron EmighRadix Labsaaron@radixlabs.com
Image Recognition Simple idea: recognize logos
Image Recognition Maybe not so simple…
Image Recognition Fully render, then retrieve sub-images
Education Why Johnny can’t identify phish…
Unmask Deceptive Links <P>To go to a surprising place via a cloaked URL, click on <A HREF="http://security.ebay.com@phisher.com">this link.</A> <P>To go to a surprising place via a cloaked URL with a password, click on <A HREF="http://security.ebay.com:password@phisher.com">this link.</A> <P>To go to a surprising place via an open redirect, click on <A HREF="http://redirect.ebaysecurity.com?url=phisher.com">this link.</A> <P>To go to a surprising place via misleading link, click on <A HREF="http://phisher.com">http://security.ebay.com.</A>
Unmask Deceptive Links <P>To go to a surprising place via a cloaked URL, click on <A HREF="http://security.ebay.com@phisher.com">this link.</A> <P>To go to a surprising place via a cloaked URL with a password, click on <A HREF="http://security.ebay.com:password@phisher.com">this link.</A> <P>To go to a surprising place via an open redirect, click on <A HREF="http://redirect.ebaysecurity.com?url=phisher.com">this link.</A> <P>To go to a surprising place via misleading link, click on <A HREF="http://phisher.com">http://security.ebay.com.</A>
Secure Path (That Was Then) Login: aaron Password: ******
Anti-Phishing Technology Chokepoints and Countermeasures Aaron EmighRadix Labsaaron@radixlabs.com