A Human in Every APE: Delineating and Evaluating the Human Analysis Systems of Anti-Phishing Entities

A Human in Every APE: Delineating and Evaluating the Human Analysis Systems of Anti-Phishing Entities
复制标题

DOI:
10.1007/978-3-031-09484-2_9
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
B. Acharya;Phani Vadrevu
B. Acharya;Phani Vadrevu
中科院分区:
其他
文献类型:
--
作者:
B. Acharya;Phani Vadrevu

文献摘要

相似文献

我们对一些流行的反钓鱼实体(APE)进行了大规模的评估。作为其中的一部分,我们向7个APE提交了CAPTCHA挑战的蜂蜜网站阵列。对APE访问期间的“点击率”进行的分析显示,有强有力的证据表明,存在着强大的人工分析系统与自动爬虫系统。总而言之,我们估计提交给4个APE(Google安全浏览,Microsoft SmartScreen,Bitdefender和Netcraft)的URL中有多达10%到24%可能被人类分析师访问。与以前的工作相比,这些测量结果为网络安全提供了一个非常乐观的前景,因为它们首次显示了广泛的人工分析系统的存在,以解决可能具有挑战性的自动爬虫分析可疑URL。这一发现使我们有机会对APE的人工分析系统的鲁棒性进行首次系统研究,揭示了其中一些明显的弱点。我们看到,我们研究的所有APE都受到缺乏地理位置和客户端设备多样性等问题的影响,使其人类系统暴露于有针对性的规避攻击。除此之外,我们还发现了整个APE生态系统中的一个特定弱点,该弱点可以通过利用Web传感器API输出中的差异来创建专门针对Android/Chrome设备的长期钓鱼页面。我们证明了这一点的帮助下,10个人工钓鱼网站,生存无限期,尽管反复报告给所有的APE。我们建议缓解所有这些问题。我们还与所有受影响的APE进行了详细的披露流程,试图说服他们采取这些缓解措施。
We conducted a large-scale evaluation of some popular Anti-Phishing Entities (APEs). As part of this, we submitted arrays of CAPTCHA challenge-laden honey sites to 7 APEs. An analysis of the “click-through rates” during the visits from the APEs showed strong evidence for the presence of formidable human analysis systems in conjunction with automated crawler systems. In summary, we estimate that as many as 10% to 24% of URLs submitted to each of 4 APEs (Google Safe Browsing, Microsoft SmartScreen, Bitdefender and Netcraft) were likely visited by human analysts. In contrast to prior works, these measurements present a very optimistic picture for web security as, for the first time, they show presence of expansive human analysis systems to tackle suspicious URLs that might otherwise be challenging for automated crawlers to analyze.This finding allowed us an opportunity to conduct the first systematic study of the robustness of the human analysis systems of APEs which revealed some glaring weaknesses in them. We saw that all the APEs we studied fall prey to issues such as lack of geolocation and client device diversity exposing their human systems to targeted evasive attacks. Apart from this, we also found a specific weakness across the entire APE ecosystem that enables creation of long-lasting phishing pages targeted exclusively against Android/Chrome devices by capitalizing on discrepancies in web sensor API outputs. We demonstrate this with the help of 10 artificial phishing sites that survived indefinitely despite repeated reporting to all APEs. We suggest mitigations for all these issues. We also conduct an elaborate disclosure process with all affected APEs in an attempt to persuade them to pursue these mitigations.