Skip to main content
BBC NEWS / TECHNOLOGY
Graphics VersionBBC Sport Home
News Front Page | Africa | Americas | Asia-Pacific | Europe | Middle East | South Asia | UK | Business | Health | Science & Environment | Technology | Entertainment | Also in the news | Have Your Say |
Wednesday, 5 April 2006, 12:25 GMT 13:25 UK

Research reveals phishing hooks

Hands on keyboard, BBC Sophisticated phishing scams could be catching out 90% of those that see them, research suggests.

The academic study looked at whether web users could tell legitimate online bank websites from the fakes produced by phishers.

Though many phishing sites were easy to spot, the best were judged real by almost all participants.

It found that users ignored most of the visual cues on browsers that warn people that they are being scammed.

Dangerous game

Those running the study said website designers needed to re-think ways of flagging dangers to users.

The study looked at bogus websites created by phishing gangs and what made users believe that these sites were legitimate. Industry statistics suggest that, on average, 5% of those that get phishing e-mails visit an associated website and are conned into handing over data.

Although low, this figure is far more than the phishing gangs need to turn a healthy profit.

The study, carried out by Rachna Dhamija, a postdoctoral fellow at the Center for Research on Computation and Society at Harvard University, Professor Doug Tygar in the department of Computer Science at Berkeley and Professor Marti Hearst at Berkeley, suggests that on relatively sophisticated scams, many times more people are taken in.

SPOTTING PHISHING SITES


The study presented real online banking and fake phishing sites to subjects to see if they could tell the two types apart.

On average, 40% of users failed to spot the phishing sites. The most sophisticated site caught out 90% of the 22 people participating.

The study revealed that people were caught out because they were generally ignorant about what did, and did not, indicate that a site was legitimate.

For instance, few of those participating looked at the domain name, such as bbc.co.uk, being displayed in a browser address bar.

Users generally did not look at the address bar, status bar or other security indicators that could flag if they had unwittingly strayed on to a phishing site.

The problem, said the researchers, was that "the indicators of trust presented by the browser are trivial to spoof".

Many participants also ignored more direct warnings contained in pop-up windows that a site may not be legitimate.

The researchers also said phishing gangs were being successful because many of the scams being mounted were very sophisticated and could catch out even seasoned users.

The academics said the results would help educate users about relevant dangers and to help those who create websites know which attacks succeed and why.

The researchers said: "These results illustrate that standard security indicators are not effective for a substantial fraction of users, and suggest that alternative approaches are needed."

The trio of researchers said the traditional security approach looks at what can be made secure rather than work out what humans do well and exploit that to make sites safer. The team is now working on ways to make fake sites far more obvious when reached by users likely to be caught out.

The researchers presented their results at the Conference on Human Factors in Computing Systems (CHI 2006) in Montreal, Canada.



E-mail this to a friend
Related to this story:
European phishing gangs targeted (20 Mar 06 |  Technology )
Taking on Britain's banking fraudsters (15 Mar 06 |  Business )
Keeping net users safe from harm (24 Oct 05 |  Technology )
Zombie PCs growing quickly online (22 Feb 06 |  Technology )
How to stay off the suckers' list (07 Feb 06 |  Magazine )
Banks 'must tackle online fraud' (23 Jan 06 |  Business )

RELATED INTERNET LINKS:
Why Phishing Works research paper (PDF)
Rachna Dhamija
J.D. Tygar
Marti Hearst
Site Advisor
The BBC is not responsible for the content of external internet sites



SEARCH BBC NEWS: 

News Front Page | Africa | Americas | Asia-Pacific | Europe | Middle East | South Asia | UK | Business | Health | Science & Environment | Technology | Entertainment | Also in the news | Have Your Say |

NewsWatch | Notes | Contact us | About BBC News | Profiles | History

^ Back to top | BBC Sport Home | BBC Homepage | Contact us | Help | ©