PhishNet: Predictive Blacklisting to Detect Phishing Attacks

被引:0
|
作者
Prakash, Pawan [1 ]
Kumar, Manish [1 ]
Kompella, Ramana Rao [1 ]
Gupta, Minaxi [2 ]
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
[2] Indiana Univ, Bloomington, IN 47405 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing has been easy and effective way for trickery and deception on the Internet. While solutions such as URL blacklisting have been effective to some degree, their reliance on exact match with the blacklisted entries makes it easy for attackers to evade. We start with the observation that attackers often employ simple modifications (e. g., changing top level domain) to URLs. Our system, PhishNet, exploits this observation using two components. In the first component, we propose five heuristics to enumerate simple combinations of known phishing sites to discover new phishing URLs. The second component consists of an approximate matching algorithm that dissects a URL into multiple components that are matched individually against entries in the blacklist. In our evaluation with real-time blacklist feeds, we discovered around 18,000 new phishing URLs from a set of 6,000 new blacklist entries. We also show that our approximate matching algorithm leads to very few false positives (3%) and negatives (5%).
引用
收藏
页数:5
相关论文
共 50 条
  • [41] Detect Phishing by Checking Content Consistency
    Chen, Yi-Shin
    Liu, Huei-Sin
    Yu, Yi-Hsuan
    Wang, Pan-Chieh
    2014 IEEE 15TH INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION (IRI), 2014, : 109 - 119
  • [42] Tools for Investigating the Phishing Attacks Dynamics
    Lyashenko, Vyacheslav
    Kobylin, Oleg
    Minenko, Mykyta
    2018 INTERNATIONAL SCIENTIFIC-PRACTICAL CONFERENCE: PROBLEMS OF INFOCOMMUNICATIONS SCIENCE AND TECHNOLOGY (PIC S&T), 2018, : 43 - 46
  • [43] Generating Phishing Attacks using ChatGPT
    Roy, Sayak Saha
    Naragam, Krishna Vamsi
    Nilizadeh, Shirin
    arXiv, 2023,
  • [44] Online detection and prevention of phishing attacks
    Institute of Communications Engineering, PLA Univ. of Sci. and Tech., Nanjing 210007, China
    Jiefangjun Ligong Daxue Xuebao, 2007, 2 (133-138): : 133 - 138
  • [45] Examining the effectiveness of phishing filters against DNS based phishing attacks
    Purkait, Swapan
    INFORMATION AND COMPUTER SECURITY, 2015, 23 (03) : 333 - 346
  • [46] BOOST YOUR RESISTANCE TO PHISHING ATTACKS
    不详
    HARVARD BUSINESS REVIEW, 2020, 98 (05) : 17 - 20
  • [47] A Framework for Detection and Measurement of Phishing Attacks
    Garera, Sujata
    Provos, Niels
    Chew, Monica
    Rubin, Aviel D.
    WORM'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON RECURRING MALCODE, 2007, : 1 - 8
  • [48] Alerting Users About Phishing Attacks
    Desolda, Giuseppe
    Di Nocera, Francesco
    Ferro, Lauren
    Lanzilotti, Rosa
    Maggi, Piero
    Marrella, Andrea
    HCI FOR CYBERSECURITY, PRIVACY AND TRUST, 2019, 11594 : 134 - 148
  • [49] A Novel Algorithm to Detect Phishing URLs
    Hawanna, Varsharani Ramdas
    Kulkarni, V. Y.
    Rane, R. A.
    2016 INTERNATIONAL CONFERENCE ON AUTOMATIC CONTROL AND DYNAMIC OPTIMIZATION TECHNIQUES (ICACDOT), 2016, : 548 - 552
  • [50] Protecting users against phishing attacks
    Kirda, Engin
    Kruegel, Christopher
    Computer Journal, 2006, 49 (05): : 554 - 561