课题基金 / 基金详情

Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI

Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI
协作研究:SaTC:核心:中:利用浏览器内人工智能防御社会工程攻击
批准号:
2126641
负责人:
Roberto Perdisci
金额:
$40.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-10-01 至 2025-09-30

项目摘要

项目成果

Roberto Perdisci的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Web-based social engineering attacks represent a growing class of cyber-attacks that exploit weaknesses in humans' decision-making processes via pretexts, baiting, and phishing. These attacks aim at deceiving users into performing online actions that may have critical cyber security and privacy implications. For instance, users may be deceived by malicious websites into revealing sensitive personal information or installing malicious software in their devices because they believe they would get something for free (e.g., a gift card). This project makes the Internet safer by building novel and robust real-time in-browser defenses that use artificial intelligence methods to dynamically detect and block such kinds of web-based social engineering attacks before users are affected. The project artifacts have immense potential to transition to practical use via collaboration with Google and AARP. Furthermore, the project involves activities across three institutions to broaden the participation of underrepresented groups in computing.Existing web defenses often rely on reactive approaches (e.g., blocklists) that do not address social engineering attacks. Unlike previous approaches, this research introduces a novel framework for discovering, modeling, and defending against web-based social engineering attacks on both desktop and mobile environments. On the discovery front, this project introduces a web-crawler to automatically harvest, analyze, and categorize instances of social-engineering attacks, considering different browsing devices. Given the discoveries of the crawler, this project uses machine-learning approaches to model the in-browser behavior of the attacks. Finally, to defend users, the project introduces real-time in-browser defense systems that track how web pages and web push notifications are delivered to users, monitor how they are executed within the browser, and extract visual features as well as network and web-content metadata. Overall, this project's outcomes improve the research community's understanding of web-based social-engineering attacks and exerts practical impact in protecting users against these attacks.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/eurosp57164.2023.00011
发表时间: 2023-07
期刊: 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P)
影响因子: --
作者: [Jienan Liu;Pooja Pun;Phani Vadrevu;R. Perdisci]
通讯作者: Jienan Liu;Pooja Pun;Phani Vadrevu;R. Perdisci
DOI: --
发表时间: 2023
期刊:
影响因子: --
作者: [Zheng Yang;Joey Allen;Matthew Landen;R. Perdisci;Wenke Lee]
通讯作者: Zheng Yang;Joey Allen;Matthew Landen;R. Perdisci;Wenke Lee
DOI: 10.1145/3517745.3561467
发表时间: 2022-10
期刊: Proceedings of the 22nd ACM Internet Measurement Conference
影响因子: --
作者: [Karthika Subramani;William Melicher;Oleksii Starov;Phani Vadrevu;R. Perdisci]
通讯作者: Karthika Subramani;William Melicher;Oleksii Starov;Phani Vadrevu;R. Perdisci
SoK: Workerounds - Categorizing Service Worker Attacks and Mitigations
SoK:解决方法 - 对 Service Worker 攻击和缓解措施进行分类
DOI: 10.1109/eurosp53844.2022.00041
发表时间: 2022
期刊: 7th IEEE European Symposium on Security and Privacy
影响因子: --
作者: [Subramani, Karthika, Jueckstock, Jordan, Kapravelos, Alexandros, Perdisci, Roberto]
通讯作者: Perdisci, Roberto
EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks
TWC: Medium: Collaborative: Exposing and Mitigating Cross-Channel Attacks that Exploit the Convergence of Telephony and the Internet
CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models
SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)