首页> 外文期刊>IEICE transactions on information and systems >Hue Signature Auto Update System for Visual Similarity-Based Phishing Detection with Tolerance to Zero-Day Attack
【24h】

Hue Signature Auto Update System for Visual Similarity-Based Phishing Detection with Tolerance to Zero-Day Attack

机译:Hue签名自动更新系统,用于基于视觉相似度的网络钓鱼检测,可容忍零日攻击

获取原文
           

摘要

Detecting phishing websites is imperative. Among several detection schemes, the promising ones are the visual similarity-based approaches. In those, targeted legitimate website's visual features referred to as signatures are stored in SDB (Signature Database) by the system administrator. They can only detect phishing websites whose signatures are highly similar to SDB's one. Thus, the system administrator has to register multiple signatures to detect various phishing websites and that cost is very high. This incurs the vulnerability of zero-day phishing attack. In order to address this issue, an auto signature update mechanism is needed. The naive way of auto updating SDB is expanding the scope of detection by adding detected phishing website's signature to SDB. However, the previous approaches are not suitable for auto updating since their similarity can be highly different among targeted legitimate website and subspecies of phishing website targeting that legitimate website. Furthermore, the previous signatures can be easily manipulated by attackers. In order to overcome the problems mentioned above, in this paper, we propose a hue signature auto update system for visual similarity-based phishing detection with tolerance to zero-day attack. The phishing websites targeting certain legitimate website tend to use the targeted website's theme color to deceive users. In other words, the users can easily distinguish phishing website if it has highly different hue information from targeted legitimate one (e.g. red colored Facebook is suspicious). Thus, the hue signature has a common feature among the targeted legitimate website and subspecies of phishing websites, and it is difficult for attackers to change it. Based on this notion, we argue that the hue signature fulfills the requirements about auto updating SDB and robustness for attackers' manipulating. This commonness can effectively expand the scope of detection when auto updating is applied to the hue signature. By the computer simulation with a real dataset, we demonstrate that our system achieves high detection performance compared with the previous scheme.
机译:必须检测网络钓鱼网站。在几种检测方案中,有希望的方案是基于视觉相似性的方法。在那些情况下,目标合法网站的可视特征(称为签名)由系统管理员存储在SDB(签名数据库)中。他们只能检测签名与SDB高度相似的网络钓鱼网站。因此,系统管理员必须注册多个签名以检测各种钓鱼网站,并且该成本非常高。这导致了零日网络钓鱼攻击的脆弱性。为了解决此问题,需要一种自动签名更新机制。自动更新SDB的天真方法是通过向SDB添加检测到的网络钓鱼网站的签名来扩展检测范围。但是,先前的方法不适合自动更新,因为它们的相似性在目标合法网站和针对该合法网站的网络钓鱼网站的亚种之间可能存在很大差异。此外,攻击者可以轻松操纵以前的签名。为了克服上述问题,在本文中,我们提出了一种色相特征自动更新系统,用于基于视觉相似度的网络钓鱼检测,并具有零日攻击能力。针对某些合法网站的网络钓鱼网站倾向于使用目标网站的主题颜色来欺骗用户。换句话说,如果钓鱼网站的色相信息与有针对性的合法网站有很大不同(例如,红色的Facebook可疑),则用户可以轻松区分钓鱼网站。因此,色相签名在目标合法网站和网络钓鱼网站的亚种之间具有共同的特征,并且攻击者很难对其进行更改。基于此概念,我们认为,色相签名满足了有关自动更新SDB和攻击者操作的鲁棒性的要求。当自动更新应用于色相签名时,这种通用性可以有效地扩展检测范围。通过对真实数据集的计算机仿真,我们证明了与以前的方案相比,我们的系统具有较高的检测性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号