PhishInPatterns: measuring elicited user interactions at scale on phishing websites

PhishInPatterns: measuring elicited user interactions at scale on phishing websites
复制标题

DOI:
10.1145/3517745.3561467
复制
发表时间:
2022-10
期刊:
Proceedings of the 22nd ACM Internet Measurement Conference
影响因子:
--
通讯作者:
Karthika Subramani;William Melicher;Oleksii Starov;Phani Vadrevu;R. Perdisci
Karthika Subramani;William Melicher;Oleksii Starov;Phani Vadrevu;R. Perdisci
中科院分区:
其他
文献类型:
--
作者:
Karthika Subramani;William Melicher;Oleksii Starov;Phani Vadrevu;R. Perdisci

文献摘要

相似文献

尽管网络钓鱼攻击和检测系统正在被广泛研究,但网络钓鱼仍在上升,最近达到了历史最高水平。攻击变得越来越复杂,利用新的网页设计模式来增加感知的合法性,同时逃避最先进的检测器和网络安全爬虫。在本文中,我们从一个新的角度研究钓鱼攻击,重点是现代钓鱼网站是如何设计的。具体来说,我们的目标是更好地了解钓鱼网站引发的用户交互类型,以及他们的用户体验(UX)和界面(UI)设计模式如何帮助他们实现两个主要目标:i)为钓鱼网站提供专业性和合法性,以及ii)有助于逃避钓鱼检测器和Web安全爬虫。为了大规模研究网络钓鱼,我们构建了一个智能爬虫,将浏览器自动化与机器学习方法相结合,模拟用户与网络钓鱼页面的交互,并探索其UX和UI特征。使用我们的新方法,我们探索了50,000多个钓鱼网站,并进行了以下新观察:i)现代钓鱼网站经常冒充品牌(例如,Microsoft Office),但令人惊讶的是,不一定克隆或密切模仿相应的合法网站的设计; ii)他们经常使用多步骤获取个人信息(或多页)过程,以模仿用户在合法网站上的体验; iii)它们嵌入了现代用户验证系统(包括CAPTCHA);具有讽刺意味的是,iv)他们有时会通过向用户保证他们的私人数据没有被盗来结束网络钓鱼体验。我们相信,我们的研究结果可以帮助社区从用户的角度更深入地了解基于Web的网络钓鱼攻击是如何工作的,并可用于开发更准确和更强大的网络钓鱼检测器。
Despite phishing attacks and detection systems being extensively studied, phishing is still on the rise and has recently reached an all-time high. Attacks are becoming increasingly sophisticated, leveraging new web design patterns to add perceived legitimacy and, at the same time, evade state-of-the-art detectors and web security crawlers. In this paper, we study phishing attacks from a new angle, focusing on how modern phishing websites are designed. Specifically, we aim to better understand what type of user interactions are elicited by phishing websites and how their user experience (UX) and interface (UI) design patterns can help them accomplish two main goals: i) lend a sense of professionalism and legitimacy to the phishing website, and ii) contribute to evading phishing detectors and web security crawlers. To study phishing at scale, we built an intelligent crawler that combines browser automation with machine learning methods to simulate user interactions with phishing pages and explore their UX and UI characteristics. Using our novel methodology, we explore more than 50,000 phishing websites and make the following new observations: i) modern phishing sites often impersonate a brand (e.g., Microsoft Office), but surprisingly, without necessarily cloning or closely mimicking the design of the corresponding legitimate website; ii) they often elicit personal information using a multi-step (or multi-page) process, to mimic users' experience on legitimate sites; iii) they embed modern user verification systems (including CAPTCHAs); and ironically, iv) they sometimes conclude the phishing experience by reassuring the user that their private data was not stolen. We believe our findings can help the community gain a more in-depth understanding of how web-based phishing attacks work from a users' perspective and can be used to inform the development of more accurate and robust phishing detectors.