UnPhishMe: Phishing Attack Detection by Deceptive Login Simulation through an Android Mobile App

UnPhishMe: Phishing Attack Detection by Deceptive Login Simulation through an Android Mobile App
复制标题

DOI:
10.1109/asiajcis.2017.19
复制
发表时间:
2017-08
期刊:
2017 12th Asia Joint Conference on Information Security (AsiaJCIS)
影响因子:
--
通讯作者:
J. D. Ndibwile;Y. Kadobayashi;Doudou Fall
J. D. Ndibwile;Y. Kadobayashi;Doudou Fall
中科院分区:
其他
文献类型:
--
作者:
J. D. Ndibwile;Y. Kadobayashi;Doudou Fall

文献摘要

被引文献

相似文献

网络钓鱼攻击最近一直在增加。攻击者使用巧妙的社会工程技术来说服受害者点击恶意软件或欺骗性的基于登录的网页。针对此特定问题的大多数解决方案更多地关注于帮助台式计算机用户,而不是移动终端用户。移动终端用户比桌面用户更容易受到攻击,因为他们大部分时间都在线,并且他们有设备限制,例如屏幕尺寸较小和计算能力较低。本文介绍了UnPhishMe,一个有效的移动的应用程序原型,利用钓鱼网站的一个特殊的弱点:他们接受任何类型的输入信息进行身份验证。UnPhishMe使移动终端用户能够使用伪造的登录凭据创建伪造的登录帐户,每次用户打开登录网页时,该帐户都会模仿用户的登录过程并向其生成警报。UnPhishMe会确定当前登录页面是否在身份验证尝试后切换到另一个网页。它通过在页面加载时监视URL的哈希代码更改,侦听HttpURLConnection状态代码,然后决定该网站是否具有欺诈性。我们通过在Android平台上进行用户实验来测量UnPhishMe的有效性,并测试其检测精度,内存和CPU性能。结果表明,UnPhishMe使用非常少量的计算能力,可以有效地帮助用户识别钓鱼攻击,准确率达到96%。
Phishing attacks have been increasing recently. Attackers use clever social engineering techniques to convince their victims into clicking a malware or deceptive login-based webpages. Most solutions for this particular problem focus more on helping desktop computer users than mobile device users. Mobile device users are more vulnerable than their desktop counterparts because they are online most of the time and they have device limitations such as smaller screen size and low computational power. This paper presents UnPhishMe, an effective mobile application prototype that takes advantage of a particular weakness of phishing sites: they accept any kind of input information for authentication. UnPhishMe enables a mobile device user to create fake login account, with fake login credentials, that mimics user login procedure every time the user opens a login webpage and generates an alert to her. UnPhishMe determines whether the current login page shifts to another webpage after an authentication attempt. It does so by monitoring hashcode changes of the URL when the page is loading, listens to HttpURLConnection status code, and then makes a decision on whether the website is fraudulent or not. We measured the effectiveness of UnPhishMe by conducting a user experiment on android platforms and tested its detection accuracy, memory and CPU performance. The results show that UnPhishMe uses a very small amount of computational power and it is effective in assisting users to identify phishing attacks with an accuracy of 96%.