Computing Reviews
Today's Issue Hot Topics Search Browse Recommended My Account Log In
Review Help
Search
A framework for detection and measurement of phishing attacks
Garera S., Provos N., Chew M., Rubin A.  Recurring malcode (Proceedings of the 2007 ACM Workshop on Recurring Malcode, Alexandria, Virginia, Nov 2, 2007)1-8.2007.Type:Proceedings
Date Reviewed: Jan 3 2008

Several features are identified that can be used to distinguish a phishing uniform resource locator (URL). High accuracy (97.31 percent) is achieved by a logistic regression filter based on these features. An advantage of feature-based tests over content-based ones is that opening a page to observe content may have undesired side effects, such as acknowledging receipt of a credit card. Google’s infrastructure data was used for testing, as well as for some of the features.

One set of features is page based (page rank and presence on the crawl database). Another feature is domain based (whether the URL’s domain can be found on the list of known nonphishing sites). A third set of features is whether the host is obfuscated, or whether a large number of characters are present after the organization’s name in the hostname. Finally, there is a word-based feature: phishing URLs use the words “login” and “signin” much more than nonphishing URLs. Six other words are also suggestive of a phishing URL.

A logistic regression filter based on these features was trained on approximately 1,600 URLs and tested on 800 URLs, giving the 97.31 percent accuracy noted. The trained classifier analyzed Google data for 12 days, and found out that more than eight percent of the viewers of a phishing page are potential phishing victims. Ebay and Paypal were the most popular phishing targets. The investigation appears valid and thorough, and the exposition is clear. This paper is worth reading.

Reviewer:  B. Hazeltine Review #: CR135076 (0811-1126)
Bookmark and Share
  Reviewer Selected
Featured Reviewer
 
 
Security (K.4.4 ... )
 
Would you recommend this review?
yes
no
Other reviews under "Security": Date
Security fundamentals for e-commerce
Hassler V., Artech House, Inc., Norwood, MA, 2000.  409, Type: Book (9781580531085)
May 20 2002
Building firm trust online
Schoder D., Yin P. Communications of the ACM 43(12): 73-79, 2000. Type: Article
Oct 1 2001
Electronic commerce relationships: trust by design
Keen P., Ballance G., Chan S., Schrump S., Prentice Hall PTR, Upper Saddle River, NJ, 2000.  249, Type: Book (9780130170378)
Feb 1 2000
more...

E-Mail This Printer-Friendly
Send Your Comments
Contact Us
Reproduction in whole or in part without permission is prohibited.   Copyright 1999-2024 ThinkLoud®
Terms of Use
| Privacy Policy