CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in Phishing

CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in Phishing
复制标题

DOI:
10.1109/sp40001.2021.00021
复制
发表时间:
2021-05
期刊:
2021 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Penghui Zhang;Adam Oest;Haehyun Cho;Zhibo Sun;RC Johnson;Brad Wardman;Shaown Sarker;A. Kapravelos;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn
Penghui Zhang;Adam Oest;Haehyun Cho;Zhibo Sun;RC Johnson;Brad Wardman;Shaown Sarker;A. Kapravelos;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn
中科院分区:
其他
文献类型:
--
作者:
Penghui Zhang;Adam Oest;Haehyun Cho;Zhibo Sun;RC Johnson;Brad Wardman;Shaown Sarker;A. Kapravelos;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn

文献摘要

相似文献

网络钓鱼是对互联网用户的严重威胁。虽然一个广泛的生态系统可以保护用户,但钓鱼网站的复杂性越来越高,它们可以在逃避技术的帮助下逃过生态系统的检测系统,从而造成现实世界的损害。复杂的客户端规避技术(称为伪装)利用JavaScript来实现潜在受害者与网络钓鱼网站之间的复杂交互,因此在减缓或完全阻止自动缓解方面特别有效。然而,无论是流行率还是客户端的伪装的影响已经研究。在本文中,我们提出了CrawlPhish,一个框架,用于自动检测和分类客户端的伪装使用已知的钓鱼网站。我们在2018年至2019年的14个月内部署了CrawlPhish,以收集和彻底分析112,005个网络钓鱼网站的数据集。通过采用最先进的静态和动态代码分析,我们发现这些网站中有35,067个网站有1,128个不同的客户端伪装技术实现。此外,我们发现攻击者使用伪装的比例从最初的23.32%增长到数据收集期结束时的33.70%。通过我们的框架检测隐形表现出较低的假阳性率和假阴性率,分别为1.45%和1.75%。我们分析了我们检测到的技术的语义,并提出了一个分类的八种类型的逃避在三个高层次的类别:用户交互,指纹识别和机器人行为。使用150人工钓鱼网站,我们的经验表明,每一类逃避技术是有效的,以避免基于浏览器的网络钓鱼检测(一个关键的生态系统防御)。此外,通过用户研究,我们验证的技术一般不会阻止受害者的访问。因此,我们提出了一些方法,我们的方法不仅可以用来提高生态系统的能力,以减轻网络钓鱼网站与客户端伪装,但也不断识别新兴的伪装技术,因为他们是由攻击者发起。
Phishing is a critical threat to Internet users. Although an extensive ecosystem serves to protect users, phishing websites are growing in sophistication, and they can slip past the ecosystem’s detection systems—and subsequently cause real-world damage—with the help of evasion techniques. Sophisticated client-side evasion techniques, known as cloaking, leverage JavaScript to enable complex interactions between potential victims and the phishing website, and can thus be particularly effective in slowing or entirely preventing automated mitigations. Yet, neither the prevalence nor the impact of client-side cloaking has been studied.In this paper, we present CrawlPhish, a framework for automatically detecting and categorizing client-side cloaking used by known phishing websites. We deploy CrawlPhish over 14 months between 2018 and 2019 to collect and thoroughly analyze a dataset of 112,005 phishing websites in the wild. By adapting state-of-the-art static and dynamic code analysis, we find that 35,067 of these websites have 1,128 distinct implementations of client-side cloaking techniques. Moreover, we find that attackers’ use of cloaking grew from 23.32% initially to 33.70% by the end of our data collection period. Detection of cloaking by our framework exhibited low false-positive and false-negative rates of 1.45% and 1.75%, respectively. We analyze the semantics of the techniques we detected and propose a taxonomy of eight types of evasion across three high-level categories: User Interaction, Fingerprinting, and Bot Behavior.Using 150 artificial phishing websites, we empirically show that each category of evasion technique is effective in avoiding browser-based phishing detection (a key ecosystem defense). Additionally, through a user study, we verify that the techniques generally do not discourage victim visits. Therefore, we propose ways in which our methodology can be used to not only improve the ecosystem’s ability to mitigate phishing websites with client-side cloaking, but also continuously identify emerging cloaking techniques as they are launched by attackers.