首页> 外文会议>APWG Symposium on Electronic Crime Research >Inside a phisher's mind: Understanding the anti-phishing ecosystem through phishing kit analysis
【24h】

Inside a phisher's mind: Understanding the anti-phishing ecosystem through phishing kit analysis

机译:网络钓鱼者的内心:通过网络钓鱼工具包分析了解反网络钓鱼生态系统

获取原文

摘要

Phishing attacks are becoming increasingly prevalent: 2016 saw more phishing attacks than any previous year on record according to the Anti-Phishing Working Group. At the same time, the growing level of sophistication of cybercriminals must be understood for the development of effective anti-phishing systems, as phishers have extensive control over the content they serve to their victims. By examining two large, real-world datasets of phishing kits and URLs from 2016 through mid-2017, we paint a clear picture of today's anti-phishing ecosystem while inferring the higher-level motives and thought processes of phishers. We analyze the nature of server-side .htaccess filtering techniques used by phishers to evade detection by the security community. We also propose a new generic classification scheme for phishing URLs which corresponds to modern social engineering techniques and reveals a correlation between URL type and compromised infrastructure use. Our analysis identifies measures that can be taken by the security community to defeat phishers' countermeasures and increase the likelihood of a timely response to phishing. We discover that phishers have a keen awareness of the infrastructure used against them, which illustrates the ever-evolving struggle between cybercriminals and security researchers and motivates future work to positively impact online security.
机译:网络钓鱼攻击正变得越来越普遍:根据反网络钓鱼工作组的数据,2016年网络钓鱼攻击数量超过有记录的前一年。同时,由于网络钓鱼者对其提供给受害者的内容拥有广泛的控制权,因此必须了解网络犯罪分子日益复杂的水平才能开发出有效的反网络钓鱼系统。通过研究2016年至2017年中的两个大型的网络钓鱼套件和URL的真实世界数据集,我们可以清晰地了解当今的反网络钓鱼生态系统,同时推断出网络钓鱼者的更高层次的动机和思维过程。我们分析了网络钓鱼者使用的服务器端.htaccess过滤技术的本质,以逃避安全社区的检测。我们还针对网络钓鱼URL提出了一种新的通用分类方案,该方案与现代社会工程学技术相对应,并揭示了URL类型与受损的基础结构使用之间的相关性。我们的分析确定了安全团体可以采取的措施,以打败网络钓鱼者的对策,并增加及时响应网络钓鱼的可能性。我们发现网络钓鱼者对针对他们的基础设施有着敏锐的意识,这说明了网络犯罪分子和安全研究人员之间不断发展的斗争,并激发了未来的工作对在线安全产生积极影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号