PhishNet: Predictive Blacklisting to Detect Phishing Attacks

被引:0
|
作者
Prakash, Pawan [1 ]
Kumar, Manish [1 ]
Kompella, Ramana Rao [1 ]
Gupta, Minaxi [2 ]
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
[2] Indiana Univ, Bloomington, IN 47405 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing has been easy and effective way for trickery and deception on the Internet. While solutions such as URL blacklisting have been effective to some degree, their reliance on exact match with the blacklisted entries makes it easy for attackers to evade. We start with the observation that attackers often employ simple modifications (e. g., changing top level domain) to URLs. Our system, PhishNet, exploits this observation using two components. In the first component, we propose five heuristics to enumerate simple combinations of known phishing sites to discover new phishing URLs. The second component consists of an approximate matching algorithm that dissects a URL into multiple components that are matched individually against entries in the blacklist. In our evaluation with real-time blacklist feeds, we discovered around 18,000 new phishing URLs from a set of 6,000 new blacklist entries. We also show that our approximate matching algorithm leads to very few false positives (3%) and negatives (5%).
引用
收藏
页数:5
相关论文
共 50 条
  • [31] Tracking Phishing Attacks Over Time
    Cui, Qian
    Jourdan, Guy-Vincent
    Bochmann, Gregor, V
    Couturier, Russell
    Onut, Iosif-Viorel
    PROCEEDINGS OF THE 26TH INTERNATIONAL CONFERENCE ON WORLD WIDE WEB (WWW'17), 2017, : 667 - 676
  • [32] Phishing attacks and how to prevent them
    Guana-Moya, Javier
    Antonio Chiluisa-Chiluisa, Marco
    del Carmen Jaramillo-Flores, Paulina
    Naranjo-Villota, Darwin
    Rafael Mora-Zambrano, Eugenio
    Gerardo Larrea-Torres, Lenin
    2022 17TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2022,
  • [33] Phishing Attacks and Protection against Them
    Ivanov, Michael A.
    Kliuchnikova, Bogdana V.
    Chugunkov, Ilya V.
    Plaksina, Anna M.
    Proceedings of the 2021 IEEE Conference of Russian Young Researchers in Electrical and Electronic Engineering, ElConRus 2021, 2021, : 425 - 428
  • [34] A Review on Recent Phishing Attacks in Internet
    Lakhita
    Yadav, Surendra
    Bohra, Brahmdutt
    Pooja
    2015 INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND INTERNET OF THINGS (ICGCIOT), 2015, : 1312 - 1315
  • [35] Analysis of phishing attacks against students
    Andric, Jakov
    Oreski, Dijana
    Kisasondi, Tonimir
    2016 39TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2016, : 1423 - 1429
  • [36] Evaluating user susceptibility to phishing attacks
    Das, Sanchari
    Nippert-Eng, Christena
    Camp, L. Jean
    INFORMATION AND COMPUTER SECURITY, 2022, 30 (01) : 1 - 18
  • [37] An overview of phishing attacks and their detection techniques
    Dadkhah, Mehdi
    Jazi, Mohammad Davarpanah
    Mobarakeh, Majid Saidi
    Shamshirband, Shahaboddin
    Wang, Xiaojun
    Raste, Sachin
    INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2016, 9 (04) : 187 - 195
  • [38] Why phishing still works: User strategies for combating phishing attacks
    Alsharnouby, Mohamed
    Alaca, Furkan
    Chiasson, Sonia
    INTERNATIONAL JOURNAL OF HUMAN-COMPUTER STUDIES, 2015, 82 : 69 - 82
  • [39] South Africans' susceptibility to phishing attacks
    Wannenburg, Mariska C.
    Nieman, Annamart
    Steyn, Blanche
    Wannenburg, Daniel G.
    SOUTHERN AFRICAN JOURNAL OF ACCOUNTABILITY AND AUDITING RESEARCH-SAJAAR, 2023, 25 : 53 - 72
  • [40] Phishing Attacks and Protection Against Them
    Ivanov, Michael A.
    Kliuchnikova, Bogdana, V
    Chugunkov, Ilya, V
    Plaksina, Anna M.
    PROCEEDINGS OF THE 2021 IEEE CONFERENCE OF RUSSIAN YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING (ELCONRUS), 2021, : 425 - 428