UnPhishMe: Phishing Attack Detection by Deceptive Login Simulation through an Android Mobile App
UnPhishMe: Phishing Attack Detection by Deceptive Login Simulation through an Android Mobile App
复制标题
DOI:
10.1109/asiajcis.2017.19
复制
发表时间:
2017-08
期刊:
影响因子:
--
通讯作者:
J. D. Ndibwile;Y. Kadobayashi;Doudou Fall
中科院分区:
文献类型:
--
作者:
J. D. Ndibwile;Y. Kadobayashi;Doudou Fall
Phishing attacks have been increasing recently. Attackers use clever social engineering techniques to convince their victims into clicking a malware or deceptive login-based webpages. Most solutions for this particular problem focus more on helping desktop computer users than mobile device users. Mobile device users are more vulnerable than their desktop counterparts because they are online most of the time and they have device limitations such as smaller screen size and low computational power. This paper presents UnPhishMe, an effective mobile application prototype that takes advantage of a particular weakness of phishing sites: they accept any kind of input information for authentication. UnPhishMe enables a mobile device user to create fake login account, with fake login credentials, that mimics user login procedure every time the user opens a login webpage and generates an alert to her. UnPhishMe determines whether the current login page shifts to another webpage after an authentication attempt. It does so by monitoring hashcode changes of the URL when the page is loading, listens to HttpURLConnection status code, and then makes a decision on whether the website is fraudulent or not. We measured the effectiveness of UnPhishMe by conducting a user experiment on android platforms and tested its detection accuracy, memory and CPU performance. The results show that UnPhishMe uses a very small amount of computational power and it is effective in assisting users to identify phishing attacks with an accuracy of 96%.