Real-Time Client-Side Phishing Prevention Add-On

Real-Time Client-Side Phishing Prevention Add-On
复制标题

实时客户端网络钓鱼防护插件

DOI:
10.1109/icdcs.2016.44
复制
发表时间:
2016
期刊:
2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS)
影响因子:
--
通讯作者:
Nadarajah Asokan
Nadarajah Asokan
中科院分区:
--
文献类型:
--
作者:
Giovanni Armano;Samuel Marchal;Nadarajah Asokan

文献摘要

被引文献

相似文献

由于现有的用于引导用户远离钓鱼网站的解决方案通常是基于服务器的,因此它们有几个缺点:它们损害用户隐私,对在不同时间提供不同内容的适应性攻击者缺乏健壮性,并且在将网站标记为钓鱼网站后不向用户提供任何指导。为了解决这些局限性,我们提出了一种新的钓鱼防御系统,实现了我们最近开发的快速有效的钓鱼检测技术[1]。它作为客户端应用程序和浏览器外接程序实现。它使用从用户访问的网站提取的信息来检测它是否是网络钓鱼并警告用户。它还确定网络钓鱼的目标,并提供将用户重定向到那里。
Since existing solutions for steering users away from phishing websites are typically server-based, they have several drawbacks: they compromise user privacy, are not robust against adaptive attackers who serve different content at different times, and do not provide any guidance to users after flagging a website as a phish. To address these limitations, we present a new phishing prevention system implementing a fast and effective phishing detection technique we developed recently [1]. It is implemented as a client-side application and a browser add-on. It uses information extracted from website visited by the user to detect if it is a phish and warn the user. It also determines the target of the phish and offers to redirect the user there.