金钱说话:通过分析其建设成本检测一次性网络钓鱼网站

Daiki Ito, Yuta Takata, Masaki Kamizono
{"title":"金钱说话:通过分析其建设成本检测一次性网络钓鱼网站","authors":"Daiki Ito, Yuta Takata, Masaki Kamizono","doi":"10.1109/TPS-ISA56441.2022.00022","DOIUrl":null,"url":null,"abstract":"Websites unfortunately play a powerful role in delivering malicious content to users during cyberattacks. In particular, the threat of phishing websites that tricks users by abusing their corporate and brand names is increasing. Building a website requires infrastructure costs (e.g., domain name fees) and operational costs (e.g., managing server settings). Additionally, many companies spend considerable resources managing their own IT assets and security countermeasures. Even when phishing websites are taken down, attackers persist by scrapping and rebuilding them, as doing so is inexpensive. Notably, there are significant differences in website building costs between companies and attackers. In this study, we propose a method of analyzing the costs incurred in a process of building websites from domain name registration to website deployment to detect phishing websites. We evaluate our method using data from 1,082 large corporate websites and 1,163 phishing websites. As a result, our method achieves a detection performance of 95% precision and 96% recall. In addition, we show that our method still achieves a 95% recall for 866 phishing websites even after six months and the indicator of website building costs is robust to concept drift. We further discuss the applicability of the cost indicator.","PeriodicalId":427887,"journal":{"name":"2022 IEEE 4th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)","volume":"96 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Money Talks: Detection of Disposable Phishing Websites by Analyzing Its Building Costs\",\"authors\":\"Daiki Ito, Yuta Takata, Masaki Kamizono\",\"doi\":\"10.1109/TPS-ISA56441.2022.00022\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Websites unfortunately play a powerful role in delivering malicious content to users during cyberattacks. In particular, the threat of phishing websites that tricks users by abusing their corporate and brand names is increasing. Building a website requires infrastructure costs (e.g., domain name fees) and operational costs (e.g., managing server settings). Additionally, many companies spend considerable resources managing their own IT assets and security countermeasures. Even when phishing websites are taken down, attackers persist by scrapping and rebuilding them, as doing so is inexpensive. Notably, there are significant differences in website building costs between companies and attackers. In this study, we propose a method of analyzing the costs incurred in a process of building websites from domain name registration to website deployment to detect phishing websites. We evaluate our method using data from 1,082 large corporate websites and 1,163 phishing websites. As a result, our method achieves a detection performance of 95% precision and 96% recall. In addition, we show that our method still achieves a 95% recall for 866 phishing websites even after six months and the indicator of website building costs is robust to concept drift. We further discuss the applicability of the cost indicator.\",\"PeriodicalId\":427887,\"journal\":{\"name\":\"2022 IEEE 4th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)\",\"volume\":\"96 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 IEEE 4th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/TPS-ISA56441.2022.00022\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE 4th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/TPS-ISA56441.2022.00022","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

不幸的是,在网络攻击期间,网站在向用户传递恶意内容方面发挥了强大的作用。特别是,利用企业名称和品牌名称欺骗用户的钓鱼网站的威胁正在增加。建立一个网站需要基础设施成本(例如,域名费用)和运营成本(例如,管理服务器设置)。此外,许多公司花费大量资源管理自己的IT资产和安全对策。即使当网络钓鱼网站被关闭时,攻击者也会通过拆除和重建它们来坚持下去,因为这样做成本不高。值得注意的是,公司和攻击者在网站建设成本上存在显著差异。在本研究中,我们提出了一种分析从域名注册到网站部署的网站建设过程中所产生的成本的方法来检测网络钓鱼网站。我们使用来自1,082个大型企业网站和1,163个钓鱼网站的数据来评估我们的方法。结果表明,该方法的检测精度为95%,召回率为96%。此外,我们表明,即使在六个月后,我们的方法仍然对866个钓鱼网站达到95%的召回率,并且网站建设成本的指标对概念漂移是稳健的。我们进一步讨论了成本指标的适用性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Money Talks: Detection of Disposable Phishing Websites by Analyzing Its Building Costs
Websites unfortunately play a powerful role in delivering malicious content to users during cyberattacks. In particular, the threat of phishing websites that tricks users by abusing their corporate and brand names is increasing. Building a website requires infrastructure costs (e.g., domain name fees) and operational costs (e.g., managing server settings). Additionally, many companies spend considerable resources managing their own IT assets and security countermeasures. Even when phishing websites are taken down, attackers persist by scrapping and rebuilding them, as doing so is inexpensive. Notably, there are significant differences in website building costs between companies and attackers. In this study, we propose a method of analyzing the costs incurred in a process of building websites from domain name registration to website deployment to detect phishing websites. We evaluate our method using data from 1,082 large corporate websites and 1,163 phishing websites. As a result, our method achieves a detection performance of 95% precision and 96% recall. In addition, we show that our method still achieves a 95% recall for 866 phishing websites even after six months and the indicator of website building costs is robust to concept drift. We further discuss the applicability of the cost indicator.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信