Free Security Portal
Become a member of Rosiello Security, right now!
Menu principale
Top Downloads
Recent Downloads
Statistics
     

(1) 2 3 »
Anti-Phishing Security Strategy by Angelo Rosiello
Posted by angelo on 2008/7/15 18:40:00 (30 reads)

Presentation about Anti-Phishing Security Strategy.
This lecture was given in Amsterdam, Black Hat 2008.

  0   Article ID : 15
A Layout-Similarity-Based Approach for Detecting Phishing Pages
Posted by angelo on 2007/9/22 13:30:00 (609 reads)

Phishing is a current social engineering attack that results in online identity theft. In a phishing attack, the attacker persuades the victim to reveal confidential information by using web site spoofing techniques. Typically, the captured information is then used to make an illegal economic profit by purchasing goods or undertaking online banking transactions. Although simple in nature, because of their effectiveness, phishing attacks still remain a great source of concern for organizations with online customer services.
In previous work, we have developed AntiPhish, a phishing protection system that prevents sensitive user information from being entered on phishing sites. The drawback is that this system requires cooperation from the user and occasionally raises false alarms. In this paper, we present an extension of our system (called DOMAntiPhish) that mitigates the shortcomings of our previous system. In particular, our novel approach leverages layout similarity information to distinguish between malicious and benign web pages. This makes it possible to reduce the involvement of the user and significantly reduces the false alarm rate. Our experimental evaluation demonstrates that our solution is feasible in practice.

To view the full article click here.

  0   Article ID : 11
Design of a Synchronous Stream Cipher from Hash Functions
Posted by angelo on 2007/8/27 20:50:00 (632 reads)

We consider a simple and secure way to realize a synchronous stream cipher from iterated hash functions. It is similar to the OFB mode where the underlying block cipher algorithm is replaced with the keyed hash function, adopting the secret suffix method. We analyzed the key, the keystream and the necessary properties to assume from the underlying hash function for the stream cipher to be considered secure. Motivated by our analysis we conjecture that the most efficient way to break the proposed stream cipher is to break the hash function or through exhaustive search for the keyspace K of k bits, that requires O(2^k) operations.

To view the full article click here.

  0   Article ID : 13
Introduzione alle Architetture dei Calcolatori
Posted by angelo on 2007/8/8 22:10:00 (588 reads)

Introduzione alle Architetture dei Calcolatori.
Per leggere l'articolo clicca qui.

  0   Article ID : 14
Introduzione ai Sistemi Operativi
Posted by angelo on 2006/11/25 13:30:00 (652 reads)

Testo sui sistemi operativi moderni.
Lulu edition.

Clicca qui.

  0   Article ID : 10
(1) 2 3 »
Login
Username:

Password:


Lost Password?

Register now!