TRIDENT: Towards Detecting and Mitigating Web-based Social Engineering Attacks

被引:0
|
作者
Yang, Zheng [1 ]
Allen, Joey [1 ]
Landen, Matthew [1 ]
Perdisci, Roberto [1 ,2 ]
Lee, Wenke [1 ]
机构
[1] Georgia Inst Technol, Atlanta, GA 30332 USA
[2] Univ Georgia, Athens, GA USA
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the weakest link in cybersecurity, humans have become the main target of attackers who take advantage of sophisticated web-based social engineering techniques. These attackers leverage low-tier ad networks to inject social engineering components onto web pages to lure users into websites that the attackers control for further exploitation. Most of these exploitations are Web-based Social Engineering Attacks (WSEAs), such as reward and lottery scams. Although researchers have proposed systems and tools to detect some WSEAs, these approaches are very tailored to specific scam techniques (i.e., tech support scams, survey scams) only. They were not designed to be effective against a broad set of attack techniques. With the ever-increasing diversity and sophistication of WSEAs that any user can encounter, there is an urgent need for new and more effective in-browser systems that can accurately detect generic WSEAs. To address this need, we propose TRIDENT, a novel defense system that aims to detect and block generic WSEAs in real-time. TRIDENT stops WSEAs by detecting Social Engineering Ads (SE-ads), the entry point of general web social engineering attacks distributed by low-tier ad networks at scale. Our extensive evaluation shows that TRIDENT can detect SE-ads with an accuracy of 92.63% and a false positive rate of 2.57% and is robust against evasion attempts. We also evaluated TRIDENT against the state-of-the-art ad-blocking tools. The results show that TRIDENT outperforms these tools with a 10% increase in accuracy. Additionally, TRIDENT only incurs 2.13% runtime overhead as a median rate, which is small enough to deploy in production.
引用
收藏
页码:6701 / 6718
页数:18
相关论文
共 50 条
  • [41] Model of the engineering collaborative design web-based
    Xiao, Lifeng
    Chinese Journal of Mechanical Engineering (English Edition), 2000, 13 (SUPPL.): : 26 - 30
  • [42] Interactive Web-based tutorials for engineering education
    Cleaver, TG
    IEEE SOUTHEASTCON '99, PROCEEDINGS, 1999, : 126 - 127
  • [43] Collaborative Web-based instruction in engineering education
    Elleboudy, AM
    Proceedings of the World Engineers' Convention 2004, Vol A, Network Engineering and Information Society, 2004, : 212 - 216
  • [44] Web-based support for cooperative software engineering
    Goguen, JA
    Lin, K
    ANNALS OF SOFTWARE ENGINEERING, 2001, 12 : 167 - 191
  • [45] Web-based software engineering process management
    Hutchens, K
    Oudshoorn, M
    Maciunas, K
    THIRTIETH HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, VOL 1: SOFTWARE TECHNOLOGY AND ARCHITECTURE, 1997, : 676 - 685
  • [46] Engineering a future for web-based learning objects
    Mohan, P
    Brooks, C
    WEB ENGINEERING, PROCEEDINGS, 2003, 2722 : 120 - 123
  • [47] A web-based system for a control engineering tutorial
    Fuente, MJ
    Pérez-Leal, J
    Rúiz-Castro, D
    INTERNET BASED CONTROL EDUCATION 2001, 2002, : 173 - 178
  • [48] A web-based system for control engineering education
    Schmid, C
    Ali, A
    PROCEEDINGS OF THE 2000 AMERICAN CONTROL CONFERENCE, VOLS 1-6, 2000, : 3463 - 3467
  • [49] An approach for Reverse Engineering of web-based applications
    Di Lucca, GA
    Di Penta, M
    Antoniol, G
    Casazza, G
    EIGHTH WORKING CONFERENCE ON REVERSE ENGINEERING, PROCEEDINGS, 2001, : 231 - 240
  • [50] A Web-based tool for control engineering teaching
    Mendez, J. Albino
    Lorenzo, Cesar
    Acosta, Leopoldo
    Torres, Santiago
    Gonzalez, Evelio
    COMPUTER APPLICATIONS IN ENGINEERING EDUCATION, 2006, 14 (03) : 178 - 187