首页> 外文会议>2nd international conference on security of information and networks 2009 >An Integrated Approach to Detect Phishing Mail Attacks A Case Study
【24h】

An Integrated Approach to Detect Phishing Mail Attacks A Case Study

机译:一种检测网络钓鱼邮件攻击的综合方法

获取原文

摘要

Phishing is a process of luring unsuspecting Internet users to a fake website by using authentic looking email and messages for fraudulent purposes. Most preferred way that the phishers employ to lure victims is through a mass email, constructed to look like an authentic message from a well-known company. Phishing website has its own technical and social problem with each other and being a very complicate and complex issue to understand and analyze, to till date there exist no known single silver bullet to solve it entirely. Here an approach to create a resilient and effective method is proposed that uses fuzzy logic to quantify and qualify all the website phishing characteristics and factors in order to detect phishing websites to assess whether phishing activity is taking place or not. The approach visualizes the webpage in three layers of which the first layer, Domain Name checker, is fully based on characteristics of hyperlinks, the second, Code Script Checker which checks out for the tricks of the attackers in a way how they use JavaScript to hide information from user, and potentially launch sophisticated attacks, and the last layer of our approach, Page Content Checker, checks for phishing site based on its sub criteria. Finally if any of them (with regards to the true one) is higher than its corresponding preset threshold then that webpage is reported as a phishing suspect.
机译:网络钓鱼是一种通过使用真实的电子邮件和欺诈性消息诱使毫无戒心的Internet用户访问虚假网站的过程。网络钓鱼者诱骗受害者的最优选方式是通过发送大量电子邮件,该电子邮件看起来像是来自知名公司的真实邮件。网络钓鱼网站彼此之间都有其自身的技术和社会问题,并且是一个非常复杂和复杂的问题,难以理解和分析,迄今为止,尚无已知的单一灵丹妙药能够完全解决该问题。在此提出一种创建弹性有效方法的方法,该方法使用模糊逻辑来量化和限定所有网站的网络钓鱼特征和因素,以便检测网络钓鱼网站以评估网络钓鱼活动是否正在发生。该方法将网页可视化为三层,其中第一层(域名检查器)完全基于超链接的特征,第二层(代码脚本检查器)以攻击者如何使用JavaScript隐藏的方式检查出攻击者的诡计。来自用户的信息,并可能发动复杂的攻击,而我们方法的最后一层,即页面内容检查器,根据其子条件检查网络钓鱼站点。最终,如果其中任何一个(关于真实的一个)高于其相应的预设阈值,则该网页被报告为网络钓鱼嫌疑人。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号