Machine Learning-Enabled Attacks on Anti-Phishing Blacklists

被引:0
|
作者
Li, Wenhao [1 ]
Laghari, Shams Ul Arfeen [2 ]
Manickam, Selvakumar [1 ]
Chong, Yung-Wey [3 ]
Li, Binyong [4 ]
机构
[1] Univ Sains Malaysia, Cybersecur Res Ctr, Gelugor 11800, Penang, Malaysia
[2] Bahrain Polytech Isa Town, Fac Engn Design Informat & Commun Technol EDICT, Sch ICT, Isa Town, Bahrain
[3] Univ Sains Malaysia, Sch Comp Sci, Gelugor 11800, Penang, Malaysia
[4] Chengdu Univ Informat Technol, Sch Cybersecur, Chengdu 610225, Peoples R China
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Blocklists; Phishing; Browsers; Security; Chatbots; Accuracy; Internet; Feature extraction; Deep learning; Uniform resource locators; Anti-phishing blacklist; cloaking technique; evasion technique; machine learning; phishing website; phishing; social engineering;
D O I
10.1109/ACCESS.2024.3516754
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The exponential rise of phishing attacks has become a critical threat to online security, exploiting both system vulnerabilities and human psychology. Although anti-phishing blacklists serve as a primary defense mechanism, they are limited by incomplete coverage and delayed updates, making them susceptible to evasion by sophisticated attackers. This study presents a comprehensive security analysis of anti-phishing blacklists and introduces two novel cloaking attacks-Feature-Driven Cloaking and Transport Layer Security (TLS)-Based Cloaking-that exploit vulnerabilities in the automated detection systems of anti-phishing entities (APEs). Using real-world data and employing machine learning techniques, the Random Forest (RF) classifier emerged as the most effective among all tested supervised classifiers, achieving 100% accuracy in distinguishing APEs from regular users and enabling attackers to bypass blacklist detection. Key findings highlight critical security flaws in major APEs, including limited infrastructure diversity, feature implementation inconsistencies, and vulnerabilities to Web Real-Time Communication (WebRTC) Internet Protocol (IP) leaks. These weaknesses extend the operational lifespan of phishing websites, heightening risks to users. The results emphasize the need for APEs to implement more robust and adaptive defenses and propose mitigation strategies to enhance the resilience of the anti-phishing ecosystem.
引用
收藏
页码:191586 / 191602
页数:17
相关论文
共 50 条
  • [31] A Honeypots Based Anti-Phishing Framework
    Chauhan, Shubhika
    Shiwani, Savita
    2014 INTERNATIONAL CONFERENCE ON CONTROL, INSTRUMENTATION, COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICCICCT), 2014, : 618 - 625
  • [32] Usability evaluation of anti-phishing toolbars
    Li, Linfeng
    Helenius, Marko
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2007, 3 (02): : 163 - 184
  • [33] Visual security is feeble for Anti-Phishing
    Leung, Chun-Ming
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON ANTI-COUNTERFEITING, SECURITY, AND IDENTIFICATION IN COMMUNICATION, 2009, : 118 - 123
  • [34] Machine Learning-Enabled Zero Touch Networks
    Shami, Abdallah
    Ong, Lyndon
    IEEE COMMUNICATIONS MAGAZINE, 2023, 61 (02) : 80 - 80
  • [35] Machine Learning-Enabled Smart Sensor Systems
    Ha, Nam
    Xu, Kai
    Ren, Guanghui
    Mitchell, Arnan
    Ou, Jian Zhen
    ADVANCED INTELLIGENT SYSTEMS, 2020, 2 (09)
  • [36] Machine learning-enabled multiplexed microfluidic sensors
    Dabbagh, Sajjad Rahmani
    Rabbi, Fazle
    Dogan, Zafer
    Yetisen, Ali Kemal
    Tasoglu, Savas
    BIOMICROFLUIDICS, 2020, 14 (06)
  • [37] Emerging Phishing Trends and Effectiveness of the Anti-Phishing Landing Page
    Gupta, Srishti
    Kumaraguru, Ponnurangam
    PROCEEDINGS OF THE 2014 APWG SYMPOSIUM ON ELECTRONIC CRIME RESEARCH (ECRIME), 2014,
  • [38] An Approach to the Implementation of the Anti-Phishing Tool for Phishing Websites Detection
    Alnajim, Abdullah
    Munro, Malcolm
    2009 INTERNATIONAL CONFERENCE ON INTELLIGENT NETWORKING AND COLLABORATIVE SYSTEMS (INCOS 2009), 2009, : 105 - +
  • [39] MACHINE LEARNING-ENABLED ZERO TOUCH NETWORKS
    Shami, Abdallah
    Ong, Lyndon
    IEEE COMMUNICATIONS MAGAZINE, 2023, 61 (06) : 50 - 50
  • [40] Towards Personalized Game-Based Learning in Anti-Phishing Education
    Roepke, Rene
    Schroeder, Ulrik
    Drury, Vincent
    Meyer, Ulrike
    2020 IEEE 20TH INTERNATIONAL CONFERENCE ON ADVANCED LEARNING TECHNOLOGIES (ICALT 2020), 2020, : 65 - 66