Phishing for Legitimacy: The Use of SSL Certificates to Ensnare Internet Users

Mohammed Awad, Aisha El Allam, Khouloud Salameh, Reem Al Mazrouei
{"title":"Phishing for Legitimacy: The Use of SSL Certificates to Ensnare Internet Users","authors":"Mohammed Awad, Aisha El Allam, Khouloud Salameh, Reem Al Mazrouei","doi":"10.1109/ICECTA57148.2022.9990241","DOIUrl":null,"url":null,"abstract":"This paper examines the impact of making Hypertext Transfer Protocol Secure (HTTPS) certificates more accessible to the public. On the one hand, such an approach facilitates the process for small and large businesses to acquire certifications from Certificate Authorities (CAs), making their clients feel secure. On the other hand, such accessibility enabled many phishers to take advantage of this and pose as legitimate entities. This paper illustrates the phishers' eagerness to imitate existing websites. Furthermore, we will explore the role and responsibility of several parties, namely the Certificate Authority (CA), the browser provider, the website, and the Internet users. The paper also analyzes the results of a survey conducted to determine university students' understanding of HTTPS meaning and offers recommendations to overcome this issue.","PeriodicalId":337798,"journal":{"name":"2022 International Conference on Electrical and Computing Technologies and Applications (ICECTA)","volume":"62 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-11-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 International Conference on Electrical and Computing Technologies and Applications (ICECTA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICECTA57148.2022.9990241","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

This paper examines the impact of making Hypertext Transfer Protocol Secure (HTTPS) certificates more accessible to the public. On the one hand, such an approach facilitates the process for small and large businesses to acquire certifications from Certificate Authorities (CAs), making their clients feel secure. On the other hand, such accessibility enabled many phishers to take advantage of this and pose as legitimate entities. This paper illustrates the phishers' eagerness to imitate existing websites. Furthermore, we will explore the role and responsibility of several parties, namely the Certificate Authority (CA), the browser provider, the website, and the Internet users. The paper also analyzes the results of a survey conducted to determine university students' understanding of HTTPS meaning and offers recommendations to overcome this issue.
网络钓鱼的合法性:使用SSL证书诱骗互联网用户
本文研究了使公众更容易访问超文本传输协议安全(HTTPS)证书的影响。一方面,这种方法简化了小型和大型企业从证书颁发机构(ca)获取证书的过程,使其客户感到安全。另一方面,这种可访问性使许多钓鱼者能够利用这一点并冒充合法实体。这篇论文说明了钓鱼者急于模仿现有网站。此外,我们将探讨多方的角色和责任,即证书颁发机构(CA)、浏览器提供商、网站和互联网用户。本文还分析了一项调查的结果,以确定大学生对HTTPS含义的理解,并提出了克服这一问题的建议。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信