Needle in a Haystack: Tracking Down Elite Phishing Domains in the Wild

被引:81
|
作者
Tian, Ke [1 ]
Jan, Steve T. K. [1 ]
Hu, Hang [1 ]
Yao, Danfeng [1 ]
Wang, Gang [1 ]
机构
[1] Virginia Tech, Dept Comp Sci, Blacksburg, VA 24061 USA
关键词
D O I
10.1145/3278532.3278569
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today's phishing websites are constantly evolving to deceive users and evade the detection. In this paper, we perform a measurement study on squatting phishing domains where the websites impersonate trusted entities not only at the page content level but also at the web domain level. To search for squatting phishing pages, we scanned five types of squatting domains over 224 million DNS records and identified 657K domains that are likely impersonating 702 popular brands. Then we build a novel machine learning classifier to detect phishing pages from both the web and mobile pages under the squatting domains. A key novelty is that our classifier is built on a careful measurement of evasive behaviors of phishing pages in practice. We introduce new features from visual analysis and optical character recognition (OCR) to overcome the heavy content obfuscation from attackers. In total, we discovered and verified 1,175 squatting phishing pages. We show that these phishing pages are used for various targeted scams, and are highly effective to evade detection. More than 90% of them successfully evaded popular blacklists for at least a month.
引用
收藏
页码:429 / 442
页数:14
相关论文
共 6 条
  • [1] Needle in a Haystack: Spotting and recognising micro-expressions "in the wild"
    Gan, Y. S.
    See, John
    Khor, Huai-Qian
    Liu, Kun-Hong
    Liong, Sze-Teng
    NEUROCOMPUTING, 2022, 503 : 283 - 298
  • [2] Finding a Needle in a Haystack: The Role of Electrostatics in Target Lipid Recognition by PH Domains
    Lumb, Craig N.
    Sansom, Mark S. P.
    PLOS COMPUTATIONAL BIOLOGY, 2012, 8 (07)
  • [3] The needle and the haystack: single molecule tracking to probe the transcription factor search in eukaryotes
    Mazzocca, Matteo
    Fillot, Tom
    Loffreda, Alessia
    Gnani, Daniela
    Mazza, Davide
    BIOCHEMICAL SOCIETY TRANSACTIONS, 2021, 49 (03) : 1121 - 1132
  • [4] RNA Mango - Finding a Needle in a Haystack: Tracking Rhodopsin mRNA using RNA Aptamers
    Breen, Jennifer B.
    Trujillo, Alexandria J.
    Butler, Mark Christian
    Rao, Sriganesh Ramachandra
    Sullivan, Jack M.
    INVESTIGATIVE OPHTHALMOLOGY & VISUAL SCIENCE, 2017, 58 (08)
  • [5] How to find a needle in a haystack: a systematic review on targeting KRAS wild-type pancreatic cancer
    Mouawad, Antoine
    Habib, Sofia
    Boutros, Marc
    Attieh, Fouad
    Kourie, Hampig Raphael
    FUTURE ONCOLOGY, 2024,
  • [6] Driving earlier clinical attrition: if you want to find the needle, burn down the haystack. Considerations for biomarker development
    Peck, Richard W.
    DRUG DISCOVERY TODAY, 2007, 12 (7-8) : 289 - 294