ArticleslgStudy

science

IDN homograph attack

IDN homograph attack is a science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand IDN homograph attack rather than just read about it. In short: An internationalized domain name (IDN) homograph attack (also homoglyph attack) is a method used by malicious parties to deceive computer users about the identity of the remote system they are communicating with. This is achieved by exploiting the fact that many different characters look alike and the user is unlikely to spot a subtle substitution.

IDN homograph attack — main illustration
IDN homograph attack — illustration

Key takeaways

  • IDN homograph attack belongs to science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect IDN homograph attack to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of IDN homograph attack from memory before moving on to harder problems.

Reference excerpt

An internationalized domain name (IDN) homograph attack (also homoglyph attack) is a method used by malicious parties to deceive computer users about the identity of the remote system they are communicating with. This is achieved by exploiting the fact that many different characters look alike and the user is unlikely to spot a subtle substitution. For example, the Cyrillic, Greek and Latin alphabets each have a letter ⟨o⟩ that has the same shape but have different code points. This kind of spoofing attack is also known as script spoofing. Unicode supports numerous scripts (writing systems), and, for a number of reasons, similar-looking characters (such as Greek Ο, Latin O, and Cyrillic О) each has its own code point despite being homoglyphs. Their incorrect or malicious usage is potentially an opportunity for security attacks. Thus, for example, a regular user of exаmple.com (exаmple.com) may be lured to click on it unquestioningly as an apparently familiar link, unaware that the third letter is not the Latin character ⟨a⟩ but rather the Cyrillic character ⟨а⟩ and is thus an entirely different domain from the intended one. The registration of homographic domain names is akin to typosquatting, in that both forms of attacks use a similar-looking name to a more established domain to fool a user. The major difference is that in typosquatting the perpetrator attracts victims by relying on natural transposition errors commonly made when a URL is entered manually, while in homograph spoofing the perpetrator deceives the victims by presenting visually indistinguishable hyperlinks. Indeed, it would be a rare accident for a web user to type, for example, a Cyrillic letter within an otherwise English word, turning, say, "bank" into "bаnk". There are cases in which an abusive registration can use both typosquatting and homograph spoofing; the pairs of l/I, i/j, and 0/O are all both close together on keyboards and, depending on the typeface (computer font), in some cases can be difficult or impossible to distinguish visually.

History

An early nuisance of this kind, pre-dating the Internet and even text terminals, was the confusion between l (lowercase letter "L") / 1 (the number "one") and O (capital letter for vowel "o") / 0 (the number "zero"). Some typewriters even omitted digits 0 and 1, as users could type a lowercase L or uppercase O instead. On computers, where the zero/O distinction often matters, slashed zeros became widely used so they could be clearly distinguished from Os when reading or typing. Even earlier, handwriting provided rich opportunities for confusion. A notable example is the etymology of the word "zenith". The translation from the Arabic "samt" included the scribe's confusing of "m" into "ni". This was common in medieval blackletter, which did not connect the vertical columns on the letters i, m, n, or u, making them difficult to distinguish when several were in a row. The latter, as well as "rn"/"m"/"rri" ("RN"/"M"/"RRI") confusion, is still possible for a human eye even with modern advanced computer technology. Unicode contributes to homograph attacks due to its combining characters, accents, several types of hyphen, etc., often due to inadequate rendering support, especially with smaller font sizes and the wide variety of fonts. Intentional look-alike character substitution with different alphabets has been known in various contexts. For example, Faux Cyrillic has been used as an amusement or attention-grabber and "Volapuk encoding", in which Cyrillic script is represented by similar Latin characters, was used in early days of the Internet as a way to overcome the lack of support for the Cyrillic alphabet. Another example is that vehicle registration plates can have both Cyrillic (for domestic usage in Cyrillic script countries) and Latin (for international driving) with the same letters. Registration plates that are issued in Greece are limited to using letters of the Greek alphabet that have homoglyphs in the Latin alphabet, as European Union regulations require the use of Latin letters.

Homographs in ASCII ASCII has several characters or pairs of characters that look alike and are known as homographs (or homoglyphs). Spoofing attacks based on these similarities are known as homograph spoofing attacks. For example, 0 (the number zero) and O (the letter), l (lowercase "L"), and I (uppercase "i"). In a typical example of a hypothetical attack, someone could register a domain name that appears almost identical to an existing domain but goes somewhere else. For example, the domain "rnicrosoft.com" begins with "r" and "n", not "m". Other examples are G00GLE.COM which looks much like GOOGLE.COM in some fonts. Using a mix of uppercase and lowercase characters, googIe.com (capital i, not lowercase L) looks much like google.com in some fonts. PayPal was a target of a phishing scam exploiting this, using the domain PayPaI.com. In certain narrow-spaced fonts such as Tahoma (the default in the address bar in Windows XP), placing a c in front of a j, l or i will produce homoglyphs such as cl cj ci (d g a).

… excerpt ends here. Continue reading the full article.

Illustrations

IDN homograph attack: Top: Thai glyphs rendered in a modern font (IBM Plex) in which they resemble Latin glyphs.Bottom: The same glyphs rendered with traditional loops.
Top: Thai glyphs rendered in a modern font (IBM Plex) in which they resemble Latin glyphs.Bottom: The same glyphs rendered with traditional loops.

Worked examples

Example 1 — a first encounter with IDN homograph attack

Start with the simplest possible case. Write down what IDN homograph attack claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to IDN homograph attack before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about IDN homograph attack ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of IDN homograph attack

In research
IDN homograph attack appears in science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses IDN homograph attack in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
IDN homograph attack is common in secondary-school and first-year university syllabi. It links to neighbouring topics Deception, Internationalized domain names, Nonstandard spelling, so understanding it makes those chapters shorter.
In everyday life
Look for IDN homograph attack outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study IDN homograph attack in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what IDN homograph attack means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain IDN homograph attack out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is IDN homograph attack in simple terms?

An internationalized domain name (IDN) homograph attack (also homoglyph attack) is a method used by malicious parties to deceive computer users about the identity of the remote system they are communicating with. This is achieved by exploiting the fact that many different characters look alike and…

Why does IDN homograph attack matter?

Because it connects several science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study IDN homograph attack?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on IDN homograph attack.

Tags

  • Deception
  • Internationalized domain names
  • Nonstandard spelling
  • Obfuscation
  • Orthography
  • Unicode
  • Web security exploits

Keep exploring