CFP last date
20 January 2025
Reseach Article

QR Code Security: Mitigating the Issue of Quishing (QR Code Phishing)

by Godwin Awuah Amoah, Hayfron-Acquah J.B.
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 184 - Number 33
Year of Publication: 2022
Authors: Godwin Awuah Amoah, Hayfron-Acquah J.B.
10.5120/ijca2022922425

Godwin Awuah Amoah, Hayfron-Acquah J.B. . QR Code Security: Mitigating the Issue of Quishing (QR Code Phishing). International Journal of Computer Applications. 184, 33 ( Oct 2022), 34-39. DOI=10.5120/ijca2022922425

@article{ 10.5120/ijca2022922425,
author = { Godwin Awuah Amoah, Hayfron-Acquah J.B. },
title = { QR Code Security: Mitigating the Issue of Quishing (QR Code Phishing) },
journal = { International Journal of Computer Applications },
issue_date = { Oct 2022 },
volume = { 184 },
number = { 33 },
month = { Oct },
year = { 2022 },
issn = { 0975-8887 },
pages = { 34-39 },
numpages = {9},
url = { https://ijcaonline.org/archives/volume184/number33/32528-2022922425/ },
doi = { 10.5120/ijca2022922425 },
publisher = {Foundation of Computer Science (FCS), NY, USA},
address = {New York, USA}
}
%0 Journal Article
%1 2024-02-07T01:23:03.956147+05:30
%A Godwin Awuah Amoah
%A Hayfron-Acquah J.B.
%T QR Code Security: Mitigating the Issue of Quishing (QR Code Phishing)
%J International Journal of Computer Applications
%@ 0975-8887
%V 184
%N 33
%P 34-39
%D 2022
%I Foundation of Computer Science (FCS), NY, USA
Abstract

To accommodate new technologies and communication methods, cybersecurity must advance. For security experts, especially those working in fields like digital forensics, new technologies provide both opportunities and challenges. New technologies like smartphones and new ways of disseminating information, like social media, might provide difficulties. Use of QR (Quick Response) codes is one of the rapidly expanding interface technologies. This paper explores privacy issues that might arise with QR codes and other information security-harming technologies. Additionally, it emphasizes the necessity for experts in the field to solve security concerns raised by the increasing use of QR codes. Each URL's words were extracted using a count vectorizer, and the URLs that were part of the QR code were used to obtain features. To distinguish between legitimate and phishing URLs, traits and words were tokenized, and naive Bayesian machine learning classification techniques were used in a recursive loop alongside logistic regression. A very accurate model was created, aiding in the reduction of quishing behaviour.

References
  1. “Aalto University”. [Online]. Available: https://research.aalto.fi/portal/en/. [ Accessed 20 04 2022].
  2. Chuang, J.C., Hu, Y.C., Ko, H.J. (2010). A Novel Secret Sharing Technique Using QRCode. International Journal of Image Processing (IJIP) 4(5) 468-475
  3. Gao, J., Kulkarni, V., Ranavat, H., Chang, L., Mei, H. (2009). A 2D Barcode-Based Mobile Payment System. In: Multimedia and Ubiquitous Engineering, 2009. MUE’09. Third International Conference on, IEEE 320-329
  4. ISO/IEC 18004:2000. (2000).Ínformation technology-Automatic identification and data capture techniques – Bar Code symbology-QR Code “.
  5. Kharraz, A., Kirda, E., Robertson, W., Balzarotti, D., &Francillon, A. A. (2014). Optical delusions: A study ofmalicious QR codes in the wild. Proceedings - 44th AnnualIEEE/IFIP International Conference on DependableSystems and Networks, DSN 2014, (December), 192–203.https://doi.org/10.1109/DSN.2014.103
  6. Krombholz, K., Fr¨uhwirt, P., Kieseberg, P., Kapsalis, I., Huber, M., Weippl, E. (2014). QR Code Security: A Survey of Attacks and Challenges for Usable Security. In: International Conference on Human Aspects of Information Security, Privacy, and Trust, Springer 79-90
  7. Narayanan, A.S. (2012). QR Codes and Security Solutions. International Journal of Computer Science and Telecommunications 3(7) 69-71
  8. Peng, K., Sanabria, H., Wu, D., Zhu, C. (2014). Security Overview of QR Codes. Student project in the MIT course 6.857,’14
  9. T. Ishihara and M. Niimi, "Compatible 2D-Code HavingTamper Detection System with QR-Code," (2014). TenthInternational Conference on Intelligent Information Hiding andMultimedia Signal Processing, Kitakyushu, 2014, pp. 493-496.DOI: 10.1109/IIH-MSP.2014.129
  10. Yao, H., & Shin, D. (2013). Towards preventing QR code-based attacks on android phones using security warnings.Proceedings of the 8th ACM SIGSAC Symposium onInformation, Computer, and Communications Security -ASIA CCS ’13, 341.https://doi.org/10.1145/2484313.2484357
  11. Banu, M. N., & Banu, S. M. (2013). A Comprehensive Study of Phishing Attacks. International Journal of ComputerScience and Information Technologies, 4(6), 783 786.Retrievedfromhttp://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.643.766&rep=rep1&type=pdf
  12. Tao, L. (2017). QR code scams rise in China, putting epayment security in spotlight | South China Morning Post. South China Morning Post. Retrieved from http://www.scmp.com/business/china business/article/2080841/rise-qr-code-scams-china-putsOnline-payment-security.
  13. Shaikh, A. N., Shabut, A. M., & Hossain, M. A. (2017). Aliterature review on phishing crime, prevention review andinvestigation of gaps. SKIMA 2016 - 2016 10th International Conference on Software, Knowledge, Information Management and Application.
Index Terms

Computer Science
Information Sciences

Keywords

Quick Response Code Naïve Bayes Natural Language Processing Logistic Regression Machine Learning Feature Extraction True Positive True Negative False Positive False Negative