Repository logo
  • English
  • Deutsch
  • Français
Log In
New user? Click here to register.Have you forgotten your password?
  1. Home
  2. CRIS
  3. Publication
  4. Verifiable Labels for Digital Services: A New Approach to Phishing Detection
 

Verifiable Labels for Digital Services: A New Approach to Phishing Detection

URI
https://arbor.bfh.ch/handle/arbor/44725
Version
Published
Date Issued
2024
Author(s)
Gassmann, Maël  
IDAS / Identity and Access Management (IAM)  
Laube, Annett
IDAS / Identity and Access Management (IAM)  
Type
Article
Language
English
Subjects

Trust

Anti-Phishing

Digital Label

Reputation

Abstract
Users often feel unsafe and unsecure when using digital services. For normal users lacking a technical background, it is difficult to recognize a website’s legitimacy. This makes them vulnerable to cyberthreats such as phishing attacks. In order to solve this issue, many organizations use corporate designs or logos to guide users through their websites. However, these files can be easily copied. More technical means are also advertised as solutions, like trusted Transport Layer Security (TLS) certificates with Extended Validation (EV) certificates, but they are too complicated for non-technical users and barely change the outcome. Right now, users lack a way to easily verify that they are using the intended digital service. Verifiable Labels uses cryptographic identifiers—e.g., from the TLS Public Key Infrastructure (PKI)—to bind an entity’s label to its identifiable key pair, is a potential solution. Instead of trying to provide automated trust, Verifiable Labels acknowledge the presence of ill-intentioned entities. In order to differentiate them from trustworthy actors, cryptographic tools are used to define metrics, which allow a user client to form easily understandable recommendations and analyze a certain actor’s reputation, thus allowing users to naturally develop an opinion and make an educated guess as to whether an entity is trustworthy or not. The end goal would be that most websites asking for some level of trust use Verifiable Labels. This not only has the potential to directly impact Internet users, but also to act as a guiding light for security companies. Since all participating websites would be listed with their reputation metrics, it becomes easier to identify high-risk websites and perform pertinent in-depth analysis in order to take action against phishers faster.
DOI
https://doi.org/10.24451/dspace/11515
Journal or Serie
International Journal on Advances in Software
ISSN
1942-2628
Publisher URL
https://www.iariajournals.org/software/soft_v17_n12_2024_paged.pdf
Organization
Technik und Informatik  
Institute for Data Applications and Security (IDAS)  
IDAS / Identity and Access Management (IAM)  
Volume
17
Issue
1&2
Publisher
IARIA
Submitter
Laube, Annett
Citation apa
Gassmann, M., & Laube, A. (2024). Verifiable Labels for Digital Services: A New Approach to Phishing Detection. In International Journal on Advances in Software (Vol. 17, Issues 1 & 2, pp. 59–67). IARIA. https://doi.org/10.24451/dspace/11515
File(s)
Loading...
Thumbnail Image
Download

open access

Name

soft_v17_n12_2024_6.pdf

Description
Version published
License
Attribution-NonCommercial-ShareAlike 4.0 International
Size

1020.11 KB

Format

Adobe PDF

Checksum (MD5)

606ae3b8b5e061fd1133de846df328e6

About ARBOR

Built with DSpace-CRIS software - System hosted and mantained by 4Science

  • Cookie settings
  • Privacy policy
  • End User Agreement
  • Send Feedback
  • Our institution