作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (8): 195-197. doi: 10.3969/j.issn.1000-3428.2008.08.069

• 安全技术 • 上一篇    下一篇

可信计算技术在防钓鱼攻击中的应用

徐 锐,王震宇,康新振   

  1. (解放军信息工程大学信息工程学院,郑州 450002)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-04-20 发布日期:2008-04-20

Application of Trusted Computing Technology in Anti-fishing

XU Rui, WANG Zhen-yu, KANG Xin-zhen   

  1. (Institute of Information Engineering, PLA Information Engineering University, Zhengzhou 450002)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-04-20 Published:2008-04-20

摘要: 钓鱼攻击手段的多样性及其攻击后果的严重性给用户身份信息等私密数据的管理带来巨大威胁。该文分析了当今主要几类钓鱼攻击的手段,剖析其攻击原理,并在分析比较现有的几种密钥保护机制的特点的基础上,将可信计算技术与安全套接字相结合,提出一种抵御钓鱼攻击的方法。根据钓鱼攻击的特点,进行了安全性能分析,表明其能有效抵御钓鱼攻击。

关键词: 可信计算, 钓鱼攻击, 证书, 密钥

Abstract: The diversity and severity of fishing attacks bring great threats to confidential data management such as identity management. This paper proposes a method which combines trusted computing technology and SSL(Secure Socket Layer) to prevent fishing attacks based on comparing current mechanisms for preventing fishing after introducing some main kinds of current fishing attacks and analyzing the rationale of it. The security analysis shows that the proposed method can prevent current main kinds of fishing attacks effectively.

Key words: trusted computing, fishing attack, certificate, key

中图分类号: