Phishing Sites and Prevention Measures

Fu-an Zhou · International Journal of Security and Its Applications · 2015

With the growing number of Internet users in online transactions, the number of phishing sites is also increasing rapidly, the threat of malicious attack front is extended, the means are ever-changing, which gives great economic losses to China's Internet users and businesses, and caused a serious impediment to online financial services and the healthy development of e-business applications.Facing of the growing phishing epidemic, the initiative alone to enhance awareness of Internet users to avoid "phishing" is not enough.This paper analyzes phishing sites based on deception trick, focusing on the Internet user side, made several recommendations to strengthen their resistance to phishing sites. Key words: Phishing sites; prevention; measuresPhishing sites scam is one kind of online fraud, refers to defraud behavior to get user accounts, property, and the file by false web site."Interaction" is one of the features of phishing sites scams, firstly is the cheater tricking users to access web site, and then is the operations activity such as the user to view and access the web site, cheat by user filling form, get the user account, password, and other information.Without the user response, phishing site fraud will not be success.But in the situation of network users lacking basic safety consciousness and awareness, phishing site has a very large living space.As the technology development used by the phishing site, many internet users with many years online shopping experience are caught in a trap of phishing sites. Phishing Site Overview The Concept of Phishing SitesSo-called "phishing" is one kind of network fraud, refers to the criminals use of a variety of means, fake real website URL and page content, or use a loophole in the real web server program insert a dangerous HTML code in some of the web page in site, in order to defraud the user bank or credit card numbers, passwords and other private information. The Classification of Phishing SitesAccording to using different methods to entice users to visit phishing websites, phishing websites can be divided into passive access type phishing site (ordinary phishing site) and taking the initiative to attack phishing site (special phishing website).1.2.1.Passive Access Type Phishing Site (Ordinary Phishing Site): Passive phishing access type refers to a phishing site after completion of the erection, first of all, let users 1 This paper is supported by the scientific research fund project launched by the young teachers of Beijing Technology and Business University in 2102Project No. QNJJ2012-12 This paper is supported by students' scientific research and entrepreneurial action plan project of Beijing Technology and Business University in 2013

Read the paper · More papers on PaperTik