Off-the-Hook: An Efficient and Usable Client-Side Phishing Prevention Application

被引:55
|
作者
Marchal, Samuel [1 ]
Armano, Giovanni [2 ]
Grondahl, Tommi [1 ]
Saari, Kalle [1 ]
Singh, Nidhi [3 ]
Asokan, N. [1 ]
机构
[1] Aalto Univ, Secure Syst Grp, Espoo 02150, Finland
[2] Portaltech Reply, London, England
[3] McAfee Gmbh, D-60528 Frankfurt, Germany
基金
芬兰科学院;
关键词
Phishing webpage detection; phishing prevention; phishing target identification; machine learning; web security; browser add-on; WEBPAGES;
D O I
10.1109/TC.2017.2703808
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing is a major problem on theWeb. Despite the significant attention it has received over the years, there has been no definitive solution. While the state-of-the-art solutions have reasonably good performance, they suffer from several drawbacks including potential to compromise user privacy, difficulty of detecting phishing websites whose content change dynamically, and reliance on features that are too dependent on the training data. To address these limitationswe present a newapproach for detecting phishing webpages in real-time as they are visited by a browser. It relies on modeling inherent phisher limitations stemming from the constraints they face while building a webpage. Consequently, the implementation of our approach, Off-the-Hook, exhibits several notable properties including high accuracy, brand-independence and good language-independence, speed of decision, resilience to dynamic phish and resilience to evolution in phishing techniques. Off-the-Hook is implemented as a fully-client-side browser add-on, which preserves user privacy. In addition, Off-the-Hook identifies the target website that a phishing webpage is attempting to mimic and includes this target in itswarning. We evaluated Off-the-Hook in two different user studies. Our results show that users prefer Off-the-Hook warnings to Firefox warnings.
引用
收藏
页码:1717 / 1733
页数:17
相关论文
共 48 条
  • [21] Client-Side Optimization Strategies for Communication-Efficient Federated Learning
    Mills, Jed
    Hu, Jia
    Min, Geyong
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2022, 60 (07) : 60 - 66
  • [22] Collective caching: Application-aware client-side file caching
    Liao, WK
    Coloma, K
    Choudhary, A
    Ward, L
    Russell, E
    Tideman, S
    [J]. 14TH IEEE INTERNATIONAL SYMPOSIUM ON HIGH PERFORMANCE DISTRIBUTED COMPUTING, PROCEEDINGS, 2005, : 81 - 90
  • [23] Secure and Efficient Proof of Ownership Scheme for Client-Side Deduplication in Cloud Environments
    Al-Amer, Amer
    Ouda, Osama
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (12) : 916 - 923
  • [24] An Efficient Distributed Concurrency Control Scheme for Transactional Systems with Client-Side Caching
    Bukhari, Fahren
    Shrivastava, Santosh
    [J]. 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS & 2012 IEEE 9TH INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (HPCC-ICESS), 2012, : 1074 - 1081
  • [25] Secure and Efficient Proof of Ownership Scheme for Client-Side Deduplication in Cloud Environments
    Al-Amer, Amer
    Ouda, Osama
    [J]. International Journal of Advanced Computer Science and Applications, 2021, 12 (12): : 916 - 923
  • [26] Efficient Federated Learning with Adaptive Client-Side Hyper-Parameter Optimization
    Kundroo, Majid
    Kim, Taehong
    [J]. 2023 IEEE 43RD INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, ICDCS, 2023, : 973 - 974
  • [27] A framework for efficient and anonymous Web usage mining based on client-side tracking
    Shahabi, C
    Banaei-Kashani, F
    [J]. WEBKDD 2001 - MINING WEB LOG DATA ACROSS ALL CUSTOMERS TOUCH POINTS, 2002, 2356 : 113 - 144
  • [28] Secure and efficient client-side data deduplication with public auditing in cloud storage
    Dang, Qianlong
    Ma, Hua
    Liu, Zhenhua
    Xie, Ying
    [J]. International Journal of Network Security, 2020, 22 (03) : 462 - 475
  • [29] Combating phishing and script-based attacks: a novel machine learning framework for improved client-side security
    Hong, Jiwon
    Kim, Hyeongmin
    Oh, Suhyeon
    Im, Yerin
    Jeong, Hyeonseong
    Kim, Hyunmin
    Jang, Eunkueng
    Kim, Kyounggon
    [J]. Journal of Supercomputing, 2025, 81 (01):
  • [30] Efficient Client-Side Deduplication of Encrypted Data With Public Auditing in Cloud Storage
    Youn, Taek-Young
    Chang, Ku-Young
    Rhee, Kyung-Hyune
    Shin, Sang Uk
    [J]. IEEE ACCESS, 2018, 6 : 26578 - 26587