Hide metadata

dc.date.accessioned2017-09-23T15:54:28Z
dc.date.available2018-08-06T22:31:11Z
dc.date.created2017-09-08T13:55:23Z
dc.date.issued2017
dc.identifier.citationMavroeidis, Vasileios Nicho, Mathew . Quick Response Code Secure: A Cryptographically Secure Anti-Phishing Tool for QR Code Attacks. Lecture Notes in Computer Science. 2017, 10446, 313-324
dc.identifier.urihttp://hdl.handle.net/10852/58491
dc.description.abstractThe two-dimensional quick response (QR) codes can be misleading due to the difficulty in differentiating a genuine QR code from a malicious one. Since the vulnerability is practically part of their design, scanning a malicious QR code can direct the user to cloned malicious sites resulting in revealing sensitive information. In order to evaluate the vulnerabilities and propose subsequent countermeasures, we demonstrate this type of attack through a simulated experiment, where a malicious QR code directs a user to a phishing site. For our experiment, we cloned Google’s web page providing access to their email service (Gmail). Since the URL is masqueraded into the QR code, the unsuspecting user who opens the URL is directed to the malicious site. Our results proved that hackers could easily leverage QR codes into phishing attack vectors targeted at smartphone users, even bypassing web browsers’ safe browsing feature. In addition, the second part of our paper presents adequate countermeasures and introduces QRCS (Quick Response Code Secure). QRCS is a universal efficient and effective solution focusing exclusively on the authenticity of the originator and consequently the integrity of QR code by using digital signatures. This research was originally published in Lecture Notes in Artificial Intelligence. © 2017 Springer Verlagen_US
dc.languageEN
dc.publisherSpringer Verlag
dc.titleQuick Response Code Secure: A Cryptographically Secure Anti-Phishing Tool for QR Code Attacksen_US
dc.typeJournal articleen_US
dc.creator.authorMavroeidis, Vasileios
dc.creator.authorNicho, Mathew
cristin.unitcode185,15,0,0
cristin.unitnameDet matematisk-naturvitenskapelige fakultet
cristin.ispublishedtrue
cristin.fulltextpostprint
cristin.qualitycode1
dc.identifier.cristin1492149
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rft.jtitle=Lecture Notes in Computer Science&rft.volume=10446&rft.spage=313&rft.date=2017
dc.identifier.jtitleLecture Notes in Computer Science
dc.identifier.volume10446
dc.identifier.startpage313
dc.identifier.endpage324
dc.identifier.doihttp://dx.doi.org/10.1007/978-3-319-65127-9_25
dc.identifier.urnURN:NBN:no-61199
dc.type.documentTidsskriftartikkelen_US
dc.type.peerreviewedPeer reviewed
dc.source.issn0302-9743
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/58491/2/QRCS_Mavroeidis%25282017%2529.pdf
dc.type.versionAcceptedVersion
cristin.articleid25


Files in this item

Appears in the following Collection

Hide metadata