课题基金 / 基金详情

CAREER: Machine Learning Assisted Crowdsourcing for Phishing Defense

CAREER: Machine Learning Assisted Crowdsourcing for Phishing Defense
职业:机器学习辅助众包网络钓鱼防御
批准号:
2030521
负责人:
Gang Wang
金额:
$42.04万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-11-01 至 2024-05-31

项目摘要

项目成果

Gang Wang的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
This project aims to address the growing threat of phishing attacks, messages that try to trick people into revealing sensitive information, by combining human and machine intelligence. Existing detection methods based on machine learning and blacklists are both brittle to new attacks and somewhat lenient, in order to avoid blocking legitimate messages; as a result, widely used email systems are vulnerable to carefully crafted phishing emails. To address this, the project team will develop systems that automatically block obvious scams while forwarding less certain cases to groups of crowd workers trained to detect phishing mails. To support these workers' decision-making, the team will develop novel explanations of the system's decision making that will highlight the aspects of both the message and its algorithm that triggered the need for human judgment. The system will also aggregate these crowd decisions to generate real-time phishing alerts that can be shared to both individual users and to email systems. The project will lead to advances in interpretable machine learning, an important topic given the increasing role that artificial intelligence and machine learning systems play in society, and also increase our ability to characterize the evolution of phishing attacks and the vulnerability of internet platforms and users to those attacks over time. The project team will also use the work as an important component of new courses on usable security and outreach programs to high school teachers and students to both educate them about and increase their participation in cybersecurity research.The work is organized around three main objectives: empirical characterization of phishing risks, developing accurate and interpretable machine learning models for phishing detection, and developing reliable crowdsourcing systems for phishing alerts. The team will assess phishing risks through developing analytics tools on the effective adoption and configuration of anti-spoofing protocols in email systems, using adversarial machine learning methods to conduct black box testing on existing phishing detectors, and creating reactive honeypots that entice and respond to phishing attacks in order to collect data on not just the initial phishing emails but on attackers' behaviors throughout the course of a successful phishing attack. The data collected on phishing emails will be used to develop the machine learning models, using Convolutional Neural Network and Long Short-Term Memory based deep learning techniques to generate both suspicious features and confidence estimates of individual decisions. The suspicious features will be used to generate interpretable security cues such as text annotations or icons by first creating simpler and more interpretable machine learning models such as decision trees that mimic the local detection boundary near the target emails in the feature space. Rules in the decision tree will be mapped back to interface elements and email content to provide the warnings, and these will be compared to generic email security warnings in a series of user studies that also model people's ability to detect phishing using a variety of cues, features, and media. Those individual models, along with the confidence estimates from the phishing detection model, will then be used to drive a crowdsourcing-based system where the models of individual users' quality will be aggregated to make reliable judgments around emails the models judge as too suspicious to pass but not suspicious enough to automatically filter.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(32)
专著(0)
科研奖励(0)
会议论文
Assessing Browser-level Defense against IDN-based Phishing
评估针对基于 IDN 的网络钓鱼的浏览器级防御
DOI: --
发表时间: 2021
期刊: Proceedings of The 30th USENIX Security Symposium (USENIX Security
影响因子: --
作者: [Hu, Hang, Wang, Yang, Wang, Gang]
通讯作者: Wang, Gang
Measuring DNS-over-HTTPS performance around the world
测量全球 DNS-over-HTTPS 性能
DOI: 10.1145/3487552.3487849
发表时间: 2021
期刊: The Internet Measurement Conference (IMC'21
影响因子: --
作者: [Chhabra, Rishabh, Murley, Paul, Kumar, Deepak, Bailey, Michael, Wang, Gang]
通讯作者: Wang, Gang
Can you trust what you see online?
你能相信你在网上看到的吗?
DOI: 10.33424/futurum381
发表时间: 2023
期刊: Futurum Careers
影响因子: --
作者: [Wang, Gang, Mink, Jaron]
通讯作者: Mink, Jaron
Explaining Why Fake Photos are Fake: Does It Work?
解释为什么假照片是假的:它有效吗?
DOI: 10.1145/3567558
发表时间: 2023
期刊: Proceedings of the ACM on Human-Computer Interaction
影响因子: --
作者: [Ruffin, Margie, Wang, Gang, Levchenko, Kirill]
通讯作者: Levchenko, Kirill
29
    Travel: NSF Student Travel Grant for the 2023 ACM International Conference on Mobile Systems, Applications, and Services (MobiSys)
    Collaborative Research: SaTC: CORE: Small: Towards Label Enrichment and Refinement to Harden Learning-based Security Defenses
    SaTC: CORE: Small: Collaborative: Towards Facilitating Kernel Vulnerability Reproduction by Fusing Crowd and Machine Generated Data
    CAREER: Machine Learning Assisted Crowdsourcing for Phishing Defense
    国内基金
    海外基金
    Understanding structural evolution of galaxies with machine learning
    • 批准号:
    • 项目类别:
      省市级项目
    • 资助金额:
      10.0万元
    • 批准年份:
      2022
    • 负责人:
      Nicola Rosario Napolitano
    • 依托单位: