Securing e-voting against MITM attacks
Dimitris Mitropoulos, Diomidis D. Spinellis · 2009
Abstract—Man in the middle attacks involve the interception and retransmission of electronic messages in a way that the original parties will presume that their communication is secure. Such an attack could be a threat to any electronic voting scenario. This paper proposes a novel method for preventing this kind of attacks by including in the transaction a challenge-response test. The human end-user is asked to vote through an image-based challenge that will foil a typical automated software-based attack. The image is crafted so as to include multiple challenge nonces as a way to select the user’s vote. The approach’s strength is based on the difficulty of malicious software to falsify the image or emulate the user’s response. I.