PhishNet: Predictive Blacklisting to Detect Phishing Attacks

被引:0
|
作者
Prakash, Pawan [1 ]
Kumar, Manish [1 ]
Kompella, Ramana Rao [1 ]
Gupta, Minaxi [2 ]
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
[2] Indiana Univ, Bloomington, IN 47405 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing has been easy and effective way for trickery and deception on the Internet. While solutions such as URL blacklisting have been effective to some degree, their reliance on exact match with the blacklisted entries makes it easy for attackers to evade. We start with the observation that attackers often employ simple modifications (e. g., changing top level domain) to URLs. Our system, PhishNet, exploits this observation using two components. In the first component, we propose five heuristics to enumerate simple combinations of known phishing sites to discover new phishing URLs. The second component consists of an approximate matching algorithm that dissects a URL into multiple components that are matched individually against entries in the blacklist. In our evaluation with real-time blacklist feeds, we discovered around 18,000 new phishing URLs from a set of 6,000 new blacklist entries. We also show that our approximate matching algorithm leads to very few false positives (3%) and negatives (5%).
引用
收藏
页数:5
相关论文
共 50 条
  • [1] Digital PhishNet will combat phishing scams
    Schultz, E
    COMPUTERS & SECURITY, 2005, 24 (02) : 97 - 97
  • [2] A Computer Vision Technique to Detect Phishing Attacks
    Rao, Routhu Srinivasa
    Ali, Syed Taqi
    2015 FIFTH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORK TECHNOLOGIES (CSNT2015), 2015, : 596 - 601
  • [3] Phish and HIPS: Human interactive proofs to detect phishing attacks
    Dhamija, R
    Tygar, JD
    HUMAN INTERACTIVE PROOFS, PROCEEDINGS, 2005, 3517 : 127 - 141
  • [4] Feature Selections for the Classification of Webpages to Detect Phishing Attacks: A Survey
    Korkmaz, Mehmet
    Sahingoz, Ozgur Koray
    Diri, Banu
    2ND INTERNATIONAL CONGRESS ON HUMAN-COMPUTER INTERACTION, OPTIMIZATION AND ROBOTIC APPLICATIONS (HORA 2020), 2020, : 365 - 373
  • [5] A Predictive Model for Phishing Attacks on Mobile Intelligent Agent Systems
    Manyama, Mashako D.
    Kogeda, Okuthe P.
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS-ICCSA 2024 WORKSHOPS, PT II, 2024, 14816 : 113 - 128
  • [6] Applying Machine Learning Techniques to Detect and Analyze Web Phishing Attacks
    Cuzzocrea, Alfredo
    Martinelli, Fabio
    Mercaldo, Francesco
    IIWAS2018: THE 20TH INTERNATIONAL CONFERENCE ON INFORMATION INTEGRATION AND WEB-BASED APPLICATIONS & SERVICES, 2014, : 355 - 359
  • [7] Hybrid machine learning: A tool to detect phishing attacks in communication networks
    Abidoye A.P.
    Kabaso B.
    Intl. J. Adv. Comput. Sci. Appl., 2020, 6 (559-569): : 559 - 569
  • [8] Hybrid Machine Learning: A Tool to Detect Phishing Attacks in Communication Networks
    Abidoye, Ademola Philip
    Kabaso, Boniface
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (06) : 559 - 569
  • [9] On Collaborative Predictive Blacklisting
    Melis, Luca
    Pyrgelis, Apostolos
    De Cristofaro, Emiliano
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2018, 48 (05) : 9 - 20
  • [10] A Novel Approach to Detect Phishing Attacks using Binary Visualisation and Machine Learning
    Barlow, Luke
    Bendiab, Gueltoum
    Shiaeles, Stavros
    Savage, Nick
    2020 IEEE WORLD CONGRESS ON SERVICES (SERVICES), 2020, : 177 - 182