• DocumentCode
    1618235
  • Title

    Depress phishing by CAPTCHA with OTP

  • Author

    Leung, Chun-Ming

  • Author_Institution
    Dept. of Inf. Eng., Chinese Univ. of Hong Kong, Shatin, China
  • fYear
    2009
  • Firstpage
    187
  • Lastpage
    192
  • Abstract
    Addressing recent online banking threats, the main challenges are to enable safe online banking on a compromised host, and solving the general ignorance of security warning. There are costly hardware solutions proposed for login authentication to transaction verification. However, we are always looking for an usable solution with higher acceptance and less effort. CAPTCHA is primarily used to anti bot automated login, also, CAPTCHA base application can further provides secure PIN input against keylogger and mouse-logger for Bank´s customer. However, assuming users are always unconscious of security warning, under this interesting condition, CAPTCHA alone is nothing to anti-phishing. But, the CAPTCHA idea is still worth to be developed. In this paper, we present the Extended CAPTCHA Input System (ECIS), which we firstly extend the CAPTCHA idea to defend Real-Time Man-In-The-Middle(RT-MITM)attack and our proposed CR-MITM attack. The trick is to employ a moving CAPTCHA for input of OneTime-Password(OTP) with time restriction, which can depress MITM auto-relaying of information as well as human assisted MITM attack. Our solution reuses the large scale shipped OTP token which can save huge amount of money instead of re-design and shipping of a new hardware solution.
  • Keywords
    authorisation; bank data processing; computer crime; message authentication; CAPTCHA; OneTime-Password; anti-phishing; antibot automated login; depress phishing; keylogger; login authentication; mouse-logger; online banking threat; safe online banking; security warning; transaction verification; Authentication; Banking; Certification; Costs; Hardware; Humans; Information security; Internet; Large-scale systems; Real time systems; Authentication; CAPTCHA; Man-In-The-Middle(MITM); One Time Password; Online Banking; Phishing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Anti-counterfeiting, Security, and Identification in Communication, 2009. ASID 2009. 3rd International Conference on
  • Conference_Location
    Hong Kong
  • Print_ISBN
    978-1-4244-3883-9
  • Electronic_ISBN
    978-1-4244-3884-6
  • Type

    conf

  • DOI
    10.1109/ICASID.2009.5276926
  • Filename
    5276926