USENIX Security2021Top-tier venue
Assessing Browser-level Defense against IDN-based Phishing
Hang Hu, Steve T. K. Jan, Yang Wang, Gang Wang
Abstract
Internationalized Domain Names (IDN) allow people around the world to use their native languages for domain names. Unfortunately, because characters from different languages can look like each other, IDNs have been used to impersonate popular domains for phishing, i.e., IDN homograph. To mitigate this risk, browsers have recently introduced defense policies. However, it is not yet well understood regarding how these policies are constructed and how effective they are. In this paper, we present an empirical analysis of browser IDN policies, and a user study to understand user perception of homograph IDNs. We focus on 5 major web browsers (Chrome, Firefox, Safari, Microsoft Edge, and IE), and 2 mobile browsers (Android Chrome and iOS Safari) and analyze their current and historical versions released from January 2015 to April 2020. By treating each browser instance as a black box, we develop an automated tool to test the browser policies with over 9,000 testing cases. We find that all the tested browsers have weaknesses in their rules, leaving opportunities for attackers to craft homograph IDNs to impersonate target websites while bypassing browsers' defense. In addition, a browser's defense is not always getting stricter over time. For example, we observe Chrome has reversed its rules to re-allow certain homograph IDNs. Finally, our user study shows that the homograph IDNs that can bypass browsers' defense are still highly deceptive to users. Overall, our results suggest the need to improve the current defense against IDN homograph.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 610b6ae9-df0f-461a-9da9-43c34fc9dd41Cited by top-tier papers7
- "Are Adversarial Phishing Webpages a Threat in Reality?" Understanding the Users' Perception of Adversarial WebpagesYing Yuan, Qingying Hao, Giovanni Apruzzese, Mauro Conti et al.WWW 2024 · 18 citations
- It Doesn't Look Like Anything to Me: Using Diffusion Model to Subvert Visual Phishing DetectorsQingying Hao, Nirav Diwan, Ying Yuan, Giovanni Apruzzese et al.USENIX Security 2024 · 11 citations
- Phishing Vs. Legit: Comparative Analysis of Client-Side Resources of Phishing and Target Brand WebsitesKyungchan Lim, Jaehwan Park, Doowon KimWWW 2024 · 11 citations
- UIHash: Detecting Similar Android UIs through Grid-Based Visual Appearance RepresentationJiawei Li, Jian Mao, Jun Zeng, Qixiao Lin et al.USENIX Security 2024 · 2 citations
- How IoT Re-using Threatens Your Sensitive Data: Exploring the User-Data Disposal in Used IoT DevicesPeiyu Liu, Shouling Ji, Lirong Fu, Kangjie Lu et al.S&P 2023
Builds on13
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen et al.CCS 2017 · 166 citations
- PhishEye: Live Monitoring of Sandboxed Phishing KitsXiao Han, Nizar Kheir, Davide BalzarottiCCS 2016 · 118 citations
- Cognitive Triaging of Phishing AttacksAmber van der Heijden, Luca AllodiUSENIX Security 2019 · 100 citations
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson et al.USENIX Security 2017 · 94 citations
- End-to-End Measurements of Email Spoofing AttacksHang Hu, Gang WangUSENIX Security 2018 · 94 citations
Related papers
- Characterizing and Mitigating Phishing Attacks at ccTLD ScaleGiovane C. M. Moura, Thomas Daniels, Maarten Bosteels, Sebastian Castro et al.CCS 2024 · 7 citations
- URL Inspection Tasks: Helping Users Detect Phishing Links in EmailsDaniele Lain, Yoshimichi Nakatsuka, Kari Kostiainen, Gene Tsudik et al.USENIX Security 2025
- Breaking the Shield: Analyzing and Attacking Canvas Fingerprinting Defenses in the WildHoang Dai Nguyen, Phani VadrevuWWW 2025 · 2 citations
- Measuring Identity Confusion with Uniform Resource LocatorsJoshua Reynolds, Deepak Kumar, Zane Ma, Rohan Subramanian et al.CHI 2020 · 30 citations
- Targeted Deanonymization via the Cache Side Channel: Attacks and DefensesMojtaba Zaheri, Yossi Oren, Reza CurtmolaUSENIX Security 2022
