Supporting Law-Enforcement to Cope with Blacklisted Websites: Framework and Case Study

Supporting Law-Enforcement to Cope with Blacklisted Websites: Framework and Case Study
复制标题

DOI:
10.1109/cns56114.2022.9947260
复制
发表时间:
2022-10
期刊:
2022 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Mir Mehedi Ahsan Pritom;Shouhuai Xu
Mir Mehedi Ahsan Pritom;Shouhuai Xu
中科院分区:
其他
文献类型:
--
作者:
Mir Mehedi Ahsan Pritom;Shouhuai Xu

文献摘要

相似文献

长期以来,网络攻击者滥用网络域名和url进行网络钓鱼、网络诈骗、恶意软件攻击等各种攻击。为了防御这些攻击,URL黑名单被广泛使用。但是,这种方法有明显的弱点,特别是从执法的角度来看。特别是,执法部门不知道如何处理黑名单,因为由于与问题相关的微妙因素,不清楚需要做什么(例如,关闭主机或域)。为了帮助执法部门处理被列入黑名单的url,我们提出了一种基于机器学习(ML)的新框架,同时为执法部门提供可解释模型预测的概率分类和可解释性。我们的概率分类和可解释性措施为执法部门可靠的决策提供了基础,并消除了传统基于机器学习方法的黑箱性质。实验结果表明,该框架是实用的,在解决网站恶意问题方面具有进一步的潜力。
Cyber attackers have long abused web domains and URLs to carry out various attacks such as Phishing, web scamming, and malware attacks. In order to defend against these attacks, URL blacklisting has been widely used. However, this approach has significant weaknesses, especially from a law-enforcement point of view. In particular, the law-enforcement does not know what to do with a blacklist because it is unclear what needs to be done (e.g., shutting down a host or domain) due to the subtleties associated with the problem. In order to help the law-enforcement in dealing with blacklisted URLs, we propose a novel framework based on Machine Learning (ML) while providing the law-enforcement with probabilistic classification and interpretability of the predictions made by the interpretable model. Our probabilistic classification and interpretability measures provide a basis for law-enforcement trustworthy decision-making and remove the black-box nature of traditional ML-based approaches. Experimental results show that the framework is practical and has further potential to tackle website maliciousness.