A phish detector using lightweight search features.

Computers & Security(2016)

引用 77|浏览59
暂无评分
摘要
Web phishing is a well-known cyber-attack which is used by attackers to obtain vital information such as username, password, credit card number, social security number, and/or other credentials from Internet users via deception. A number of web phishing detection solutions have been proposed and implemented in the recent years. These solutions include the use of phishing black list, search engine, heuristics and machine learning, visual similarity techniques, DNS, access list and proactive phishing URLs detection based techniques. However, the current solutions are quite heavy in terms of their computational and communication requirements. Most of these solutions are dependent on third parties and require dedicated servers for their operation. It has been observed that search engine based solutions are the most lightweight and viable. This paper advances search engine based antiphishing research and presents the lightest possible phishing detection system, named the Lightweight Phish Detector (LPD). The LPD can run on client browsers for phishing detection. The development of LPD was done using the Google Chrome browser. Exhaustive testing has been performed to evaluate its accuracy and effectiveness. Comparisons are performed with currently available search engine based antiphishing approaches and other approaches that are currently used by popular browsers such as Chrome, Firefox, Internet Explorer, Netcraft toolbar and Cascaded Phish Detector. For testing, phishing sites reported from the Phishtank and normal sites available from Alexa ranking are used in the experiments. A true negative rate varying from 92.4% to 100% was obtained from the Alexa dataset of normal URLs while a true positive rate of 99.5% was recorded from the Phishtank URLs. Results show that the proposed scheme is very accurate. A competitive response time and intelligent action-response mechanism makes LPD a fast and intelligent antiphishing solution.
更多
查看译文
关键词
Phishing,Search engine,Lightweight,Google,Chrome
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要