Catching Transparent Phish: Analyzing and Detecting MITM Phishing Toolkits

Catching Transparent Phish: Analyzing and Detecting MITM Phishing Toolkits
复制标题

DOI:
10.1145/3460120.3484765
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Brian Kondracki;Babak Amin Azad;Oleksii Starov;Nick Nikiforakis
Brian Kondracki;Babak Amin Azad;Oleksii Starov;Nick Nikiforakis
中科院分区:
其他
文献类型:
--
作者:
Brian Kondracki;Babak Amin Azad;Oleksii Starov;Nick Nikiforakis

文献摘要

被引文献

相似文献

十多年来,网络钓鱼工具包一直在帮助攻击者自动化和简化他们的网络钓鱼活动。中间人(MITM)网络钓鱼工具包是这一领域的最新发展,其中工具包充当在线服务的恶意反向代理服务器,将实时内容镜像给用户,同时提取传输中的cre-cookie和会话cookie。这些工具进一步减少了攻击者所需的工作,自动化了2FA认证会话的收获,并大大提高了钓鱼网页的可信度。在本文中,我们提出了第一个分析的MITM网络钓鱼工具包在野外使用。通过对这些工具包的分析和实验,我们确定了可用于识别它们的内在网络级属性。基于这些属性,我们开发了一个机器学习分类器,可以以99.9%的准确率识别在线通信中存在的此类工具包。我们通过创建一个数据收集框架来监控和抓取来自公共资源的可疑URL,从而对MITM网络钓鱼工具包进行大规模的纵向研究。使用此基础设施,我们在一年内捕获了1,220个MITM钓鱼网站的数据。我们发现,MITM网络钓鱼工具包在网络钓鱼阻止列表中占据了一个盲点,只有43.7%的域和18.9%的IP地址与MITM网络钓鱼工具包相关,出现在阻止列表中,使毫无戒心的用户容易受到这些攻击。我们的研究结果表明,我们的检测方案是弹性的伪装机制,这些工具,并能够检测到以前隐藏的网络钓鱼内容。最后,我们提出了一些方法,在线服务可以利用这些工具包的指纹请求,并阻止网络钓鱼尝试,因为他们发生。
For over a decade, phishing toolkits have been helping attackers automate and streamline their phishing campaigns. Man-in-the- Middle (MITM) phishing toolkits are the latest evolution in this space, where toolkits act as malicious reverse proxy servers of online services, mirroring live content to users while extracting cre- dentials and session cookies in transit. These tools further reduce the work required by attackers, automate the harvesting of 2FA- authenticated sessions, and substantially increase the believability of phishing web pages. In this paper, we present the first analysis of MITM phishing toolkits used in the wild. By analyzing and experimenting with these toolkits, we identify intrinsic network-level properties that can be used to identify them. Based on these properties, we develop a machine learning classifier that identifies the presence of such toolkits in online communications with 99.9% accuracy. We conduct a large-scale longitudinal study of MITM phishing toolkits by creating a data-collection framework that monitors and crawls suspicious URLs from public sources. Using this infrastruc- ture, we capture data on 1,220 MITM phishing websites over the course of a year. We discover that MITM phishing toolkits occupy a blind spot in phishing blocklists, with only 43.7% of domains and 18.9% of IP addresses associated with MITM phishing toolkits present on blocklists, leaving unsuspecting users vulnerable to these attacks. Our results show that our detection scheme is resilient to the cloaking mechanisms incorporated by these tools, and is able to detect previously hidden phishing content. Finally, we propose methods that online services can utilize to fingerprint requests origi- nating from these toolkits and stop phishing attempts as they occur.