首页> 外文会议>eCrime Research Summit >The consequence of non-cooperation in the fight against phishing
【24h】

The consequence of non-cooperation in the fight against phishing

机译:非合作对抗网络钓鱼的后果

获取原文

摘要

A key way in which banks mitigate the effects of phishing is to have fraudulent websites removed or abusive domain names suspended. This ‘take-down’ is often subcontracted to specialist companies. We analyse six months of ‘feeds’ of phishing website URLs from multiple sources, including two such companies. We demonstrate that in each case huge numbers of websites may be known to others, but the company with the take-down contract remains unaware of them, or only belatedly learns that they exist. We monitored all of the websites to determine when they were removed and calculate the resultant increase in lifetimes from the take-down company not knowing that they should act. The results categorically demonstrate that significant amounts of money are being put at risk by the failure to share proprietary feeds of URLs. We analyse the incentives that prevent data sharing by take-down companies, contrasting this with the anti-virus industry - where sharing prevails - and with schemes for purchasing vulnerability information, where information about attacks is kept proprietary. We conclude by recommending that the defenders of phishing attacks start cooperatively sharing all of their data about phishing URLs with each other.
机译:银行减轻网络钓鱼效果的一个关键方式是让欺诈性网站删除或滥用域名。这个“toud-down”通常是对专业公司的分包。我们分析了来自多个来源的网络钓鱼网站URL的六个月,包括两家公司。我们证明,在每种情况下,他人都可以为他人知道大量的网站,但是与上下合同的公司仍然不知道它们,或者只姗姗来迟地了解它们存在。我们监控所有网站以确定它们何时被移除并计算出从中下公司的生命中的结果增加,而不知道他们应该采取行动。结果分摊表明,未能分享URL的专有饲料,将大量的资金投入风险。我们分析了防止利用公司的数据共享的激励措施,与反病毒行业对比 - 在其中共享 - 以及购买漏洞信息的计划,有关攻击的信息保存专有。我们通过推荐,网络钓鱼攻击的捍卫者开始协同分享所有关于网络钓鱼URL的数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号