跳到主要导航 跳到搜索 跳到主要内容

Protect sensitive sites from phishing attacks using features extractable from inaccessible phishing URLs

  • Xi'an Jiaotong University
  • Microsoft USA
  • Tsinghua University

科研成果: 书/报告/会议事项章节会议稿件同行评审

43 引用 (Scopus)

摘要

Phishing is the third cyber-security threat globally and the first cyber-security threat in China. There were 61.69 million phishing victims in China alone from June 2011 to June 2012, with the total annual monetary loss more than 4.64 billion US dollars. These phishing attacks were highly concentrated in targeting at a few major Websites. Many phishing Webpages had a very short life span. In this paper, we assume the Websites to protect against phishing attacks are known, and study the effectiveness of machine learning based phishing detection using only lexical and domain features, which are available even when the phishing Webpages are inaccessible. We propose several novel highly effective features, and use the real phishing attack data against Taobao and Tencent, two main phishing targets in China, in studying the effectiveness of each feature, and each group of features. We then select an optimal set of features in our phishing detector, which has achieved a detection rate better than 98%, with a false positive rate of 0.64% or less. The detector is still effective when the distribution of phishing URLs changes.

源语言英语
主期刊名2013 IEEE International Conference on Communications, ICC 2013
出版商Institute of Electrical and Electronics Engineers Inc.
1990-1994
页数5
ISBN(印刷版)9781467331227
DOI
出版状态已出版 - 2013
活动2013 IEEE International Conference on Communications, ICC 2013 - Budapest, 匈牙利
期限: 9 6月 201313 6月 2013

出版系列

姓名IEEE International Conference on Communications
ISSN(印刷版)1550-3607

会议

会议2013 IEEE International Conference on Communications, ICC 2013
国家/地区匈牙利
Budapest
时期9/06/1313/06/13

学术指纹

探究 'Protect sensitive sites from phishing attacks using features extractable from inaccessible phishing URLs' 的科研主题。它们共同构成独一无二的指纹。

引用此