School conducts anti-phishing research
Methods at Indiana University raising ethical, logistical questions
Tech Holiday Gift Guide |
Online holiday shopping is trickier this year For online holiday shopping this season, consider expanding your repertoire of retailers and bring your most comfy slippers. It’s going to be a more challenging effort this year than last . |
Tech and gadgets videos |
New soda machine mixes custom drinks Nov. 10: A new soda machine lets you mix and match to blend a custom-made beverage. CNBC’s Melissa Lee explains how it works. |
Video |
Auto Tech |
A better economy may lure buyers, but these trends could seal the deal. |
EVANSVILLE, Ind. - The e-mail appeared to be a routine correspondence between two friends. "Check this out!" it read, then listed a Web address.
But the note was fake, part of an online ruse called phishing that has become a scammer's favorite way to get sensitive information from unsuspecting computer users.
The catch? The scammers were Indiana University researchers, the e-mail an experiment.
"I didn't know I was being used," said Kevin McGrath, 25, a doctoral student at Indiana University whose e-mail address was one of hundreds used as "passive participants" for an experiment to study who gets duped by phishing.
As universities nationwide study ways to protect online security, methods at Indiana are raising ethical and logistical questions for researchers elsewhere: Does one have to steal to understand stealing? Should study participants know they are being attacked as part of a study? Can controlled phishing ever mimic real life?
Indiana researchers say the best way to understand online security is to act like the bad guys.
"We don't believe that you can go and ask people, 'Have you been phished?' There's a stigma associated with it. It's like asking people, 'Have you been raped?'" said Markus Jakobsson, an associate professor of informatics who directs IU's Anti-Phishing Group.
The university has conducted nearly a dozen experiments in the last two years. In one, called "Messin' With Texas," researchers learned mothers' maiden names for scores of people in Texas. Maiden names often are used as a security challenge question.
Another conducted in May found that 72 percent of more than 600 students tested on the Bloomington, Ind., campus fell for an e-mail from an account intended to look familiar that sought usernames and passwords.
By contrast, only 18 percent of 350 students in a separate control group were fooled when they received e-mails from addresses they did not recognize.
The experiments found that hackers have the most success by using hijacked Web addresses or e-mail accounts that look real. The research also showed computer users generally have little knowledge of Web site security certificates and leave themselves open to attack with poorly configured routers or operating systems.
- Discuss Story On Newsvine
-
Rate Story:
View popularLowHigh - Instant Message
MORE FROM INTERNET |
| Add Internet headlines to your news reader: |
Resource guide



