Machine Learning-Enabled Attacks on Anti-Phishing Blacklists

被引:0
|
作者
Li, Wenhao [1 ]
Laghari, Shams Ul Arfeen [2 ]
Manickam, Selvakumar [1 ]
Chong, Yung-Wey [3 ]
Li, Binyong [4 ]
机构
[1] Univ Sains Malaysia, Cybersecur Res Ctr, Gelugor 11800, Penang, Malaysia
[2] Bahrain Polytech Isa Town, Fac Engn Design Informat & Commun Technol EDICT, Sch ICT, Isa Town, Bahrain
[3] Univ Sains Malaysia, Sch Comp Sci, Gelugor 11800, Penang, Malaysia
[4] Chengdu Univ Informat Technol, Sch Cybersecur, Chengdu 610225, Peoples R China
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Blocklists; Phishing; Browsers; Security; Chatbots; Accuracy; Internet; Feature extraction; Deep learning; Uniform resource locators; Anti-phishing blacklist; cloaking technique; evasion technique; machine learning; phishing website; phishing; social engineering;
D O I
10.1109/ACCESS.2024.3516754
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The exponential rise of phishing attacks has become a critical threat to online security, exploiting both system vulnerabilities and human psychology. Although anti-phishing blacklists serve as a primary defense mechanism, they are limited by incomplete coverage and delayed updates, making them susceptible to evasion by sophisticated attackers. This study presents a comprehensive security analysis of anti-phishing blacklists and introduces two novel cloaking attacks-Feature-Driven Cloaking and Transport Layer Security (TLS)-Based Cloaking-that exploit vulnerabilities in the automated detection systems of anti-phishing entities (APEs). Using real-world data and employing machine learning techniques, the Random Forest (RF) classifier emerged as the most effective among all tested supervised classifiers, achieving 100% accuracy in distinguishing APEs from regular users and enabling attackers to bypass blacklist detection. Key findings highlight critical security flaws in major APEs, including limited infrastructure diversity, feature implementation inconsistencies, and vulnerabilities to Web Real-Time Communication (WebRTC) Internet Protocol (IP) leaks. These weaknesses extend the operational lifespan of phishing websites, heightening risks to users. The results emphasize the need for APEs to implement more robust and adaptive defenses and propose mitigation strategies to enhance the resilience of the anti-phishing ecosystem.
引用
收藏
页码:191586 / 191602
页数:17
相关论文
共 50 条
  • [21] A framework for assessment of anti-phishing preparedness
    Leung, Alvin Chung Man
    Bose, Indranil
    IMECS 2007: INTERNATIONAL MULTICONFERENCE OF ENGINEERS AND COMPUTER SCIENTISTS, VOLS I AND II, 2007, : 1020 - +
  • [22] Analysis and improvement of anti-phishing schemes
    Florencio, Dinei
    Herley, Cormac
    SECURITY AND PRIVACY IN DYNAMIC ENVIRONMENTS, 2006, 201 : 148 - +
  • [23] Anti-phishing by smart mobile device
    Han, Weili
    Wang, Yi
    Cao, Ye
    Zhou, Jiping
    Wang, Lixing
    2007 IFIP INTERNATIONAL CONFERENCE ON NETWORK AND PARALLEL COMPUTING WORKSHOPS, PROCEEDINGS, 2007, : 295 - 300
  • [24] Usability evaluation of anti-phishing toolbars
    Linfeng Li
    Marko Helenius
    Journal in Computer Virology, 2007, 3 (2): : 163 - 184
  • [25] Time Up for Phishing with Effective Anti-Phishing Research Strategies
    Chaudhary, Sunil
    Berki, Eleni
    Li, Linfeng
    Valtanen, Juri
    INTERNATIONAL JOURNAL OF HUMAN CAPITAL AND INFORMATION TECHNOLOGY PROFESSIONALS, 2015, 6 (02) : 49 - 64
  • [26] Machine Learning-Enabled Personalization of Programming Learning Feedback
    Alshammari, Mohammad T.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2025, 16 (02) : 1091 - 1097
  • [27] Towards a Competitive Two-Player Anti-phishing Learning Game
    Roepke, Rene
    Ballmann, Johannes
    GAMES AND LEARNING ALLIANCE, GALA 2023, 2024, 14475 : 56 - 66
  • [28] The Development and Evaluation of an Anti-Phishing E-Learning Intervention for Nurses
    Magdalinou, Andriana
    Kalokairinou, Athena
    Malamateniou, Flora
    Mantas, John
    DIGITAL PROFESSIONALISM IN HEALTH AND CARE: DEVELOPING THE WORKFORCE, BUILDING THE FUTURE, VOL. 298, 2022, : 165 - 166
  • [29] Mobile anti-phishing: Approaches and challenges
    Shahriar, Hossain
    Zhang, Chi
    Dunn, Stephen
    Bronte, Robert
    Sahlan, Atef
    Tarmissi, Khaled
    INFORMATION SECURITY JOURNAL, 2019, 28 (06): : 178 - 193
  • [30] NoPhish: An anti-phishing education app
    Technische Universität Darmstadt, Germany
    Lect. Notes Comput. Sci., (188-192):