首页> 外文会议>European Symposium on Research in Computer Security >DeltaPhish: Detecting Phishing Webpages in Compromised Websites
【24h】

DeltaPhish: Detecting Phishing Webpages in Compromised Websites

机译:deltaphish:检测受损网站的网络钓鱼网页

获取原文

摘要

The large-scale deployment of modern phishing attacks relies on the automatic exploitation of vulnerable websites in the wild, to maximize profit while hindering attack traceability, detection and blacklisting. To the best of our knowledge, this is the first work that specifically leverages this adversarial behavior for detection purposes. We show that phishing webpages can be accurately detected by highlighting HTML code and visual differences with respect to other (legitimate) pages hosted within a compromised website. Our system, named DeltaPhish, can be installed as part of a web application firewall, to detect the presence of anomalous content on a website after compromise, and eventually prevent access to it. DeltaPhish is also robust against adversarial attempts in which the HTML code of the phishing page is carefully manipulated to evade detection. We empirically evaluate it on more than 5,500 webpages collected in the wild from compromised websites, showing that it is capable of detecting more than 99% of phishing webpages, while only misclassifying less than 1% of legitimate pages. We further show that the detection rate remains higher than 70% even under very sophisticated attacks carefully designed to evade our system.
机译:现代网络钓鱼攻击的大规模部署依赖于野外脆弱网站的自动开发,在妨碍攻击可追溯性,检测和黑名单时最大化利润。据我们所知,这是第一个专门利用这种对抗目的的对抗行为的工作。我们表明,通过突出显示HTML代码和视觉差异,可以准确地检测网络钓鱼网页,并在受妥协的网站内托管的其他(合法)页面。我们的系统名为DeltaPhish,可以作为Web应用程序防火墙的一部分安装,以在妥协后检测网站上的异常内容的存在,并最终阻止访问它。 Deltaphish也是强大的,防止对逆势尝试进行仔细操纵网络钓鱼页面的HTML代码以逃避检测。我们在从受损网站野外收集的超过5,500个网页上凭经验评估了它,表明它能够检测超过99%的网络钓鱼网页,同时只会错误地错误地分类不到1%的合法页面。我们进一步表明,即使在非常复杂的攻击中仔细设计以避免我们的系统,检测率仍然高于70%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号