Measuring Identity Confusion with Uniform Resource Locators
Joshua Reynolds, Deepak Kumar, Zane Ma, Rohan Subramanian, Meishan Wu, Martin Shelton, Joshua Mason, Emily Stark, Michael D. Bailey
Abstract
Uniform Resource Locators (URLs) unambiguously specify host identity on the web. URLs are syntactically complex, and although software can accurately parse identity from URLs, users are frequently exposed to URLs and expected to do the same. Unfortunately, incorrect assessment of identity from a URL can expose users to attacks, such as typosquatting and phishing. Our work studies how well users can correctly determine the host identity of real URLs from common services and obfuscated "look-alike" URLs. We observe that participants employ a wide range of URL parsing strategies, and can identify real URLs 93% of time. However, only 40% of obfuscated URLs were identified correctly. These mistakes highlighted several ways in which URLs were confusing to users and why their existing URL parsing strategies fall short. We conclude with future research directions for reliably conveying website identity to users.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a0a5065c-1ddb-4854-adb9-740ffbe610ffCited by top-tier papers9
- I Don't Need an Expert! Making URL Phishing Features Human ComprehensibleKholoud Althobaiti, Nicole Meng, Kami VanieaCHI 2021 · 32 citations
- Assessing Browser-level Defense against IDN-based PhishingHang Hu, Steve T. K. Jan, Yang Wang, Gang WangUSENIX Security 2021 · 22 citations
- VeriSMS: A Message Verification System for Inclusive Patient Outreach against Phishing AttacksChenkai Wang, Zhuofan Jia, Hadjer Benkraouda, Cody Zevnik et al.CHI 2024 · 5 citations
- Tales of Favicons and Caches: Persistent Tracking in Modern BrowsersKonstantinos Solomos, John Kristoff, Chris Kanich, Jason PolakisNDSS 2021
- Scanned and Scammed: Insecurity by ObsQRity? Measuring User Susceptibility and Awareness of QR Code-Based AttacksMarvin Kowalewski, Leona Lassak, Markus Dürmuth, Theodor SchnitzlerUSENIX Security 2025
Builds on4
- How Well Do My Results Generalize? Comparing Security and Privacy Survey Results from MTurk, Web, and Telephone SamplesElissa M. Redmiles, Sean Kross, Michelle L. MazurekS&P 2019 · 222 citations
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen et al.CCS 2017 · 166 citations
- You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS CertificatesRichard Roberts, Yaelle Goldschlag, Rachel Walter, Taejoong Chung et al.CCS 2019 · 52 citations
- The Web's Identity Crisis: Understanding the Effectiveness of Website Identity IndicatorsChristopher Thompson, Martin Shelton, Emily Stark, Max Walker et al.USENIX Security 2019 · 48 citations
Related papers
- URL Inspection Tasks: Helping Users Detect Phishing Links in EmailsDaniele Lain, Yoshimichi Nakatsuka, Kari Kostiainen, Gene Tsudik et al.USENIX Security 2025
- What is this URL's Destination? Empirical Evaluation of Users' URL ReadingSara Albakry, Kami Vaniea, Maria K. WoltersCHI 2020 · 48 citations
- Misdirection of Trust: Demystifying the Abuse of Dedicated URL Shortening ServiceZhibo Zhang, Lei Zhang, Zhangyue Zhang, Geng Hong et al.NDSS 2025
- Host of Troubles: Multiple Host Ambiguities in HTTP ImplementationsJianjun Chen, Jian Jiang, Hai-Xin Duan, Nicholas Weaver et al.CCS 2016 · 49 citations
- Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom DomainsKevin Saric, Felix Savins, Gowri Sankar Ramachandran, Raja Jurdak et al.WWW 2024 · 3 citations
