Deep Dive into Client-Side Anti-Phishing: A Longitudinal Study Bridging Academia and Industry

被引:0
|
作者
Pourmohamad, Rana [1 ]
Wirsz, Steven [1 ]
Oest, Adam [1 ]
Bao, Tiffany [1 ]
Shoshitaishvili, Yan [1 ]
Wang, Ruoyu [1 ]
Doupe, Adam [1 ]
Bazzi, Rida A. [1 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
关键词
Client-side Anti-Phishing; Google SafeBrowsing; Blocklist; ATTACKS;
D O I
10.1145/3634737.3657027
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Client-side anti-phishing methods are crucial for safeguarding individuals against phishing attacks, offering a proactive approach beyond traditional blocklisting strategies. This study expands the scope to include a comprehensive evaluation of client-side antiphishing techniques within the Chrome browser, alongside an indepth analysis of academic research in the field of phishing over the past five years. Our findings highlight the inherent limitations of current client-side anti-phishing measures, which demonstrated a detection rate of only 14% for phishing websites and blocked merely 10% of login-based phishing sites within the first hour, resulting in a substantial false negative rate. Additionally, our analysis reveals that attackers can readily circumvent these defenses by altering the content of phishing websites. The study also critically assesses recent academic contributions to understand their alignment and potential integration with client-side anti-phishing frameworks. Based on these insights, we propose targeted recommendations to enhance the efficacy and responsiveness of the client-side anti-phishing ecosystem, addressing the challenges of low detection coverage, slow response times, and high rates of false negatives.
引用
收藏
页码:638 / 653
页数:16
相关论文
共 2 条
  • [1] Longitudinal Study of the Use of Client-side Security Mechanisms on the European Web
    Chen, Ping
    Desmet, Lieven
    Huygens, Christophe
    Joosen, Wouter
    [J]. PROCEEDINGS OF THE 25TH INTERNATIONAL CONFERENCE ON WORLD WIDE WEB (WWW'16 COMPANION), 2016, : 457 - 462
  • [2] A Longitudinal Study of Vulnerable Client-side Resources and Web Developers' Updating Behaviors
    Lim, Kyungchan
    Kwon, Yonghwi
    Kim, Doowon
    [J]. Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC, 2023, : 162 - 180