An evaluation of page token in OpenID Single Sign on (SSO) to thwart phishing attack

Single Sign-on (SSO) was introduced to overcome the issue of password memorability among users as researches have shown that users struggle to cope with too many sets of password as number of account increases. This is due to SSO relies on the usage of single authentication that allows users to acce...

Full description

Saved in:
Bibliographic Details
Main Authors: Zakaria, Nur Haryani, Zainul, Mohd Faizal, Katuk, Norliza, Mohamad Tahir, Hatim, Omar, Mohd Nizam
Format: Article
Language:English
Published: Universiti Teknikal Malaysia Melaka 2018
Subjects:
Online Access:http://repo.uum.edu.my/26476/1/JTECE%209%202-11%2019%2023.pdf
http://repo.uum.edu.my/26476/
http://journal.utem.edu.my/index.php/jtec/article/view/3844
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.uum.repo.26476
record_format eprints
spelling my.uum.repo.264762019-10-01T06:47:11Z http://repo.uum.edu.my/26476/ An evaluation of page token in OpenID Single Sign on (SSO) to thwart phishing attack Zakaria, Nur Haryani Zainul, Mohd Faizal Katuk, Norliza Mohamad Tahir, Hatim Omar, Mohd Nizam QA75 Electronic computers. Computer science Single Sign-on (SSO) was introduced to overcome the issue of password memorability among users as researches have shown that users struggle to cope with too many sets of password as number of account increases. This is due to SSO relies on the usage of single authentication that allows users to access to multiple websites or services. As much as it has managed to solve the memorability issue to certain extend, users were found to have skeptical in its adoption due to security concerns. Among common issues of SSO is that it is prone to several attacks like spam, link manipulation, session hacking and particularly phishing. Despite of many efforts been placed to overcome phishing attack with regards to SSO, the effectiveness of the proposed solutions are yet to be proven by conducting extensive evaluation. Thus, this study intends to conduct an evaluation on a particular solution of phishing attack call page token. Page token was proposed recently which was claimed to be able to mitigate the issue of phishing attack with regards to SSO application. The evaluation involved a control laboratory experiment with participants being recruited to experience the usage of page token as a protection mechanism against phishing attack. The results showed are promising along with several suggestions given for further enhancement. Universiti Teknikal Malaysia Melaka 2018 Article PeerReviewed application/pdf en http://repo.uum.edu.my/26476/1/JTECE%209%202-11%2019%2023.pdf Zakaria, Nur Haryani and Zainul, Mohd Faizal and Katuk, Norliza and Mohamad Tahir, Hatim and Omar, Mohd Nizam (2018) An evaluation of page token in OpenID Single Sign on (SSO) to thwart phishing attack. Journal of Telecommunication, Electronic and Computer Engineering, 1. pp. 19-23. ISSN 2289-8131 http://journal.utem.edu.my/index.php/jtec/article/view/3844
institution Universiti Utara Malaysia
building UUM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Utara Malaysia
content_source UUM Institutional Repository
url_provider http://repo.uum.edu.my/
language English
topic QA75 Electronic computers. Computer science
spellingShingle QA75 Electronic computers. Computer science
Zakaria, Nur Haryani
Zainul, Mohd Faizal
Katuk, Norliza
Mohamad Tahir, Hatim
Omar, Mohd Nizam
An evaluation of page token in OpenID Single Sign on (SSO) to thwart phishing attack
description Single Sign-on (SSO) was introduced to overcome the issue of password memorability among users as researches have shown that users struggle to cope with too many sets of password as number of account increases. This is due to SSO relies on the usage of single authentication that allows users to access to multiple websites or services. As much as it has managed to solve the memorability issue to certain extend, users were found to have skeptical in its adoption due to security concerns. Among common issues of SSO is that it is prone to several attacks like spam, link manipulation, session hacking and particularly phishing. Despite of many efforts been placed to overcome phishing attack with regards to SSO, the effectiveness of the proposed solutions are yet to be proven by conducting extensive evaluation. Thus, this study intends to conduct an evaluation on a particular solution of phishing attack call page token. Page token was proposed recently which was claimed to be able to mitigate the issue of phishing attack with regards to SSO application. The evaluation involved a control laboratory experiment with participants being recruited to experience the usage of page token as a protection mechanism against phishing attack. The results showed are promising along with several suggestions given for further enhancement.
format Article
author Zakaria, Nur Haryani
Zainul, Mohd Faizal
Katuk, Norliza
Mohamad Tahir, Hatim
Omar, Mohd Nizam
author_facet Zakaria, Nur Haryani
Zainul, Mohd Faizal
Katuk, Norliza
Mohamad Tahir, Hatim
Omar, Mohd Nizam
author_sort Zakaria, Nur Haryani
title An evaluation of page token in OpenID Single Sign on (SSO) to thwart phishing attack
title_short An evaluation of page token in OpenID Single Sign on (SSO) to thwart phishing attack
title_full An evaluation of page token in OpenID Single Sign on (SSO) to thwart phishing attack
title_fullStr An evaluation of page token in OpenID Single Sign on (SSO) to thwart phishing attack
title_full_unstemmed An evaluation of page token in OpenID Single Sign on (SSO) to thwart phishing attack
title_sort evaluation of page token in openid single sign on (sso) to thwart phishing attack
publisher Universiti Teknikal Malaysia Melaka
publishDate 2018
url http://repo.uum.edu.my/26476/1/JTECE%209%202-11%2019%2023.pdf
http://repo.uum.edu.my/26476/
http://journal.utem.edu.my/index.php/jtec/article/view/3844
_version_ 1648740700212166656
score 13.211869