首页> 外文会议>Intelligence and Security Informatics >Method for Evaluating the Security Risk of a Website Against Phishing Attacks
【24h】

Method for Evaluating the Security Risk of a Website Against Phishing Attacks

机译:评估网站遭受网络钓鱼攻击的安全风险的方法

获取原文
获取原文并翻译 | 示例

摘要

As Internet technologies evolve, phishing and pharming attacks frequently occur and diversify. In order to protect the economic loss and privacy of Internet users against the phishing attacks, several researches such as website authentication and email authentication have been studied. Although, most of them use website black-list (WBL) or website white-list (WWL), there are several weak points, such as validity of WBL DB (database) and the short life-cycle of phishing websites. That is, it is impossible to discriminate between legitimate and forged websites until the phishing attacks are detected and recorded into WBL DB. Furthermore, the existing WBL and WWL approaches hardly counter the new generation of sophisticated malware pharming attacks. In this paper, in order to overcome the limitation of WBL and WWL approaches, new approach based on the WWL approach, which can quantitatively estimate the security risk of websites that is security risk degree representing the phishing websites, is proposed.
机译:随着Internet技术的发展,网络钓鱼和域欺骗攻击经常发生并且多样化。为了保护网络用户免受网络钓鱼攻击的经济损失和隐私,已经进行了一些研究,例如网站认证和电子邮件认证。尽管其中大多数使用网站黑名单(WBL)或网站白名单(WWL),但仍存在一些弱点,例如WBL DB(数据库)的有效性和网络钓鱼网站的生命周期短。也就是说,只有在检测到网络钓鱼攻击并将其记录到WBL DB中之后,才能区分合法网站和伪造网站。此外,现有的WBL和WWL方法几乎无法抵御新一代复杂的恶意软件欺骗攻击。为了克服WBL和WWL方法的局限性,提出了一种基于WWL方法的新方法,该方法可以定量地估计网站的安全风险,即代表网络钓鱼网站的安全风险度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号