首页> 外文会议>APWG Symposium on Electronic Crime Research >Beyond the lock icon: real-time detection of phishing websites using public key certificates
【24h】

Beyond the lock icon: real-time detection of phishing websites using public key certificates

机译:锁定图标之外:使用公钥证书实时检测网络钓鱼网站

获取原文

摘要

We propose a machine-learning approach to detect phishing websites using features from their X.509 public key certificates. We show that its efficacy extends beyond HTTPS-enabled sites. Our solution enables immediate local identification of phishing sites. As such, this serves as an important complement to the existing server-based anti-phishing mechanisms which predominately use blacklists. Blacklisting suffers from several inherent drawbacks in terms of correctness, timeliness, and completeness. Due to the potentially significant lag prior to site blacklisting, there is a window of opportunity for attackers. Other local client-side phishing detection approaches also exist, but primarily rely on page content or URLs, which are arguably easier to manipulate by attackers. We illustrate that our certificate-based approach greatly increases the difficulty of masquerading undetected for phishers, with single millisecond delays for users. We further show that this approach works not only against HTTPS-enabled phishing attacks, but also detects HTTP phishing attacks with port 443 enabled.
机译:我们提出一种机器学习方法,以使用X.509公钥证书中的功能来检测网络钓鱼网站。我们证明了它的功效超出了启用HTTPS的站点的范围。我们的解决方案可以立即在本地识别网络钓鱼站点。因此,这是对现有的主要使用黑名单的基于服务器的反网络钓鱼机制的重要补充。在正确性,及时性和完整性方面,列入黑名单存在一些固有的缺陷。由于在将站点列入黑名单之前可能存在显着的滞后,因此攻击者有一个机会之窗。还存在其他本地客户端网络钓鱼检测方法,但主要依靠页面内容或URL,可以说攻击者更容易操纵这些页面内容或URL。我们说明,基于证书的方法极大地增加了伪装网络钓鱼者无法伪装的难度,对用户而言只有一毫秒的延迟。我们进一步证明,该方法不仅可用于启用HTTPS的网络钓鱼攻击,而且还可以检测到启用了端口443的HTTP网络钓鱼攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号