Opening the Blackbox of VirusTotal: Analyzing Online Phishing Scan Engines

Opening the Blackbox of VirusTotal: Analyzing Online Phishing Scan Engines
复制标题

DOI:
10.1145/3355369.3355585
复制
发表时间:
2019-10
期刊:
Proceedings of the Internet Measurement Conference
影响因子:
--
通讯作者:
Peng Peng-Peng;Limin Yang;Linhai Song;Gang Wang
Peng Peng-Peng;Limin Yang;Linhai Song;Gang Wang
中科院分区:
其他
文献类型:
--
作者:
Peng Peng-Peng;Limin Yang;Linhai Song;Gang Wang

文献摘要

被引文献

相似文献

研究人员大量使用诸如VirusTotal之类的在线扫描引擎来标记恶意网址和文件。不幸的是,人们对这些标签是如何生成的以及扫描结果的可靠性如何并不十分了解。在本文中,我们聚焦于VirusTotal及其68个第三方供应商,以研究它们对钓鱼网址的标记过程。我们通过建立自己的钓鱼网站(模仿贝宝和美国国税局)并提交网址进行扫描来进行一系列的测量。通过分析传入的网络流量以及VirusTotal上动态的标签变化,我们对VirusTotal的工作原理及其标签质量有了新的见解。其中,我们表明供应商在标记所有钓鱼网站方面存在困难,即使是最好的供应商也遗漏了我们30%的钓鱼网站。此外,扫描后结果不会立即更新到VirusTotal,而且VirusTotal的扫描结果与一些供应商自己的扫描器之间存在不一致的情况。我们的研究结果表明,需要开发更严谨的方法来评估和利用从VirusTotal获得的标签。
Online scan engines such as VirusTotal are heavily used by researchers to label malicious URLs and files. Unfortunately, it is not well understood how the labels are generated and how reliable the scanning results are. In this paper, we focus on VirusTotal and its 68 third-party vendors to examine their labeling process on phishing URLs. We perform a series of measurements by setting up our own phishing websites (mimicking PayPal and IRS) and submitting the URLs for scanning. By analyzing the incoming network traffic and the dynamic label changes at VirusTotal, we reveal new insights into how VirusTotal works and the quality of their labels. Among other things, we show that vendors have trouble flagging all phishing sites, and even the best vendors missed 30% of our phishing sites. In addition, the scanning results are not immediately updated to VirusTotal after the scanning, and there are inconsistent results between VirusTotal scan and some vendors' own scanners. Our results reveal the need for developing more rigorous methodologies to assess and make use of the labels obtained from VirusTotal.