skip to main content
10.1145/1866855.1866863acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
research-article

Empirical analysis of internet identity misuse: case study of south Korean real name system

Published:08 October 2010Publication History

ABSTRACT

Some governments like South Korea require the submission of a valid national identification number in order for users to register an account in Web services. Unfortunately, this validation system can cause a big privacy threat. Recently in South Korea, identifiers of about 2/5 Korean population were leaked by some hacking accidents. In order to lower the chances of forgery and privacy invasion using exposed information, Korean government introduced an alternative identifier system. However, we are concerned that neither old nor new identifer systems are safe against a phishing attack. In this paper, we empirically analyze the vulnerability of the alternative system. We conducted a real phishing attack experiment to complete our analysis.

References

  1. ]]i-pin. http://i-pin.kisa.or.kr/.Google ScholarGoogle Scholar
  2. ]]Identity theft and identity fraud. http://www.justice.gov/criminal/fraud/websites/idtheft.html.Google ScholarGoogle Scholar
  3. ]]2008 survey on information security. http://www.kisa.or.kr/, 2008.Google ScholarGoogle Scholar
  4. ]]Phishing activity trends report, 4th quarter 2009. http://www.antiphishing.org/, 2009.Google ScholarGoogle Scholar
  5. ]]R. Dhamija, J. D. Tygar, and M. Hearst. Why phishing works. In CHI '06: Proceedings of the SIGCHI conference on Human Factors in computing systems, pages 581--590, New York, NY, USA, 2006. ACM. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. ]]T. Dierks and C. Allen. The TLS protocol version 1.0. RFC 2246 (Informational), 1999. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. ]]T. N. Jagatic, N. A. Johnson, M. Jakobsson, and F. Menczer. Social phishing. Commun. ACM, 50(10):94--100, 2007. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. ]]M. Jakobsson. Modeling and preventing phishing attacks. In In Financial Cryptography. Springer Verlag, 2005. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. ]]H. Kim, J. H. Huh, and R. Anderson. On the security of internet banking in south korea. Technical Report RR-10-01, March 2010.Google ScholarGoogle Scholar
  10. ]]A. Litan. Phishing attack victims likely targets for identity theft, May 2004.Google ScholarGoogle Scholar
  11. ]]Microsoft. Description of activex technologies, 2007.Google ScholarGoogle Scholar

Index Terms

  1. Empirical analysis of internet identity misuse: case study of south Korean real name system

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in
        • Published in

          cover image ACM Conferences
          DIM '10: Proceedings of the 6th ACM workshop on Digital identity management
          October 2010
          70 pages
          ISBN:9781450300902
          DOI:10.1145/1866855

          Copyright © 2010 ACM

          Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

          Publisher

          Association for Computing Machinery

          New York, NY, United States

          Publication History

          • Published: 8 October 2010

          Permissions

          Request permissions about this article.

          Request Permissions

          Check for updates

          Qualifiers

          • research-article

          Acceptance Rates

          DIM '10 Paper Acceptance Rate8of16submissions,50%Overall Acceptance Rate16of34submissions,47%

          Upcoming Conference

          CCS '24
          ACM SIGSAC Conference on Computer and Communications Security
          October 14 - 18, 2024
          Salt Lake City , UT , USA

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader