Back home   |   Bookmark   |   Start page   |   Site map    
Services
News
Channels
Home & Family
Leisure
Technology
Business
Science
Site Search
Free email




Informatics scientists' 'active cookies' put bite on cyber crooks

TheAllINeed.com
(NC&T/IU) Whereas regular computer cookies, which are often used for authentication purposes, can easily be stolen from the computers where they belong, active cookies resist such attacks. This helps keep identifying information secret, which in turns stops cyber attacks.

Cookies are coded pieces of information stored on a user's computer. The cookies identify that computer, and therefore also its user, during the current and subsequent visits to a Web site. Active cookies can be used in exactly the same general manner, but are resistant to attacks by identity thieves and hackers.

"Normal computer cookies can be stolen in many ways," said Markus Jakobsson, associate professor of informatics and co-inventor of active cookies. "One way is for the attacker to interfere with what is called the domain lookup, a process when an Internet address, such as a well-known lending institution, is translated to an Internet Protocol address, which is the real address computers use to communicate."

This attack is called Domain Name System poisoning, commonly referred to as pharming, and it allows any users' cookies to be stolen. The attacker could simply target one of the many machines a computer interacts with when its users browse the Web, including a home router.

Markus Jakobsson, associate professor of informatics. (Photo: Indiana U.)
"But active cookies cannot be stolen like this, even if an attacker interferes with the DNS translation," said Jakobsson. "The reason is simple: Active cookies use one step that requires no translation."

Jakobsson and Sid Stamm, a computer science doctoral student at the School of Informatics, worked on the project with Ari Juels of RSA Laboratories in Massachusetts. Jakobsson and Juels also are co-founders of RavenWhite, a private company developing cookie technology to protect users from on-line threats.

Stamm said that if an attacker successfully interferes with the translation, then the attacker still cannot obtain all the secret information he needs to impersonate the victim.

"This allows your bank to check that you are you," said Stamm, "or at least that the person who knows your username and password also uses your computer. This could really make a difference in terms of the threat of phishing."

The reason is simple: While a cyber crook might trick a user into revealing their PIN number or password, as is commonly done in some scams, it is not enough to gain access to the user's account; they would need to steal a person's personal computer where the active cookies are stored.

The researchers claim, for example, that a user's bank can put active cookies on their clients' home and work computers.

"And you can still log in if you travel, you might just have to provide some additional identifying information then, or your bank can compare your login location with the location of your last ATM withdrawal," Jakobsson said. "Or the active cookies system used by banks can flag suspicious login transactions and see whether they result in strange transfers. Then the bank could put a hold on these transactions and verify them with their customers."

About the Author
©2006 All rights reserved

More articles
Snake-like robot
Bungee-powered backpack
Humanoid robot
Pinpoint sound
Unbelted backseat passengers
Invisible electronics
Mini-autonomous underwater vehicles
Robotic crawler
Scalable video
Carbon nanotubes
IActive cookies
Optical technologies
Electric power
Invisible electronics
Vortex generators
Motion computer models
Walking molecule
Nanoengineered
Sound sensors
Molecular memory
Quotes
If I work incessantly to the last, nature owes me another form of existence when the present one collapses. -- Goethe, 1829

If a few idiots want to risk their necks flying across the country thats fine, but nothing will ever replace trains.


Writers
If you are a writer and want to see your article published at Theallineed.com, just click here to submit.

Info
Today...
In the news...
Economic integration can spur development in Western Asia
Closer economic integration can help the Western Asian region overcome recent conflicts and political tensions and also spur progress towards internationally agreed anti-poverty goals, Secretary-General Ban Ki-moon said today.
What is your favourite foreign cuisine?
French
Spanish
Chinese
Mexican
Italian
Japanese
Other
 
Things to ponder
If the cops arrest a mime, do they tell him he has the right to remain silent?

Did you know...
The rhinoceros is most closely related to the horse.

Quote of the day
I've been on a diet for two weeks and all I've lost is two weeks.
Totie Fields

Featured article
Help Hair Grow
Hair gives natural beauty to all person which can improve the appearance, feeling, personality and expression. Shiny hair is a sign of health because the layers of the cuticle lie flat and reflect light.

 
© 2002 - 2007 Lexur