PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 1, 2018113 citations

Inside a phisher's mind: Understanding the anti-phishing ecosystem through phishing kit analysis

View Full Paper
AOAdam OestYSYeganeh SafeiADAdam Doupé

Key Points

Key points are not available for this paper at this time.

Abstract

Phishing attacks are becoming increasingly prevalent: 2016 saw more phishing attacks than any previous year on record according to the Anti-Phishing Working Group. At the same time, the growing level of sophistication of cybercriminals must be understood for the development of effective anti-phishing systems, as phishers have extensive control over the content they serve to their victims. By examining two large, real-world datasets of phishing kits and URLs from 2016 through mid-2017, we paint a clear picture of today's anti-phishing ecosystem while inferring the higher-level motives and thought processes of phishers. We analyze the nature of server-side .htaccess filtering techniques used by phishers to evade detection by the security community. We also propose a new generic classification scheme for phishing URLs which corresponds to modern social engineering techniques and reveals a correlation between URL type and compromised infrastructure use. Our analysis identifies measures that can be taken by the security community to defeat phishers' countermeasures and increase the likelihood of a timely response to phishing. We discover that phishers have a keen awareness of the infrastructure used against them, which illustrates the ever-evolving struggle between cybercriminals and security researchers and motivates future work to positively impact online security.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Oest et al. (2018) studied this question.

synapsesocial.com/papers/6a0f77f5d13714ec96fe316bhttps://doi.org/10.1109/ecrime.2018.8376206
Ask AI
Helpful
Bookmark
Share
View Full Paper