Detecting Cloud-Based Phishing Attacks by Combining Deep Learning Models

被引:3
作者
Jha, Birendra [1 ]
Atre, Medha [1 ]
Rao, Ashwini [1 ]
机构
[1] Eydle Inc, Los Angeles, CA 91107 USA
来源
2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA | 2022年
关键词
Deep Learning; Phishing; Cybersecurity;
D O I
10.1109/TPS-ISA56441.2022.00026
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Web-based phishing attacks nowadays exploit popular cloud web hosting services and apps such as Google Sites and Typeform for hosting their attacks. Since these attacks originate from reputable domains and IP addresses of the cloud services, traditional phishing detection methods such as IP reputation monitoring and blacklisting are not very effective. Here we investigate the effectiveness of deep learning models in detecting this class of cloud-based phishing attacks. Specifically, we evaluate deep learning models for three phishing detection methods-LSTM model for URL analysis, YOLOv2 model for logo analysis, and triplet network model for visual similarity analysis. We train the models using well-known datasets and test their performance on cloud-based phishing attacks in the wild. Our results qualitatively explain why the models succeed or fail. Furthermore, our results highlight how combining results from the individual models can improve the effectiveness of detecting cloud-based phishing attacks.
引用
收藏
页码:130 / 139
页数:10
相关论文
共 49 条
[31]   A layout-similarity-based approach for detecting phishing pages [J].
Rosiello, Angelo P. E. ;
Kirda, Engin ;
Kruegel, Christopher ;
Ferrandi, Fabrizio .
2007 THIRD INTERNATIONAL CONFERENCE ON SECURITY AND PRIVACY IN COMMUNICATION NETWORKS AND WORKSHOPS, 2007, :454-+
[32]  
Schroff F, 2015, PROC CVPR IEEE, P815, DOI 10.1109/CVPR.2015.7298682
[33]  
Severo E, 2018, IEEE IJCNN
[34]   "Kn0w Thy Doma1n Name": Unbiased Phishing Detection Using Domain Name Based Features [J].
Shirazi, Hossein ;
Bezawada, Bruhadeshwar ;
Ray, Indrakshi .
SACMAT'18: PROCEEDINGS OF THE 23RD ACM SYMPOSIUM ON ACCESS CONTROL MODELS & TECHNOLOGIES, 2018, :69-75
[35]  
Simonyan K, 2015, Arxiv, DOI [arXiv:1409.1556, DOI 10.48550/ARXIV.1409.1556]
[36]   Scalable logo detection by self co-learning [J].
Su, Hang ;
Gong, Shaogang ;
Zhu, Xiatian .
PATTERN RECOGNITION, 2020, 97
[37]   Comparison of Adaboost with MultiBoosting for Phishing Website Detection [J].
Subasi, Abdulhamit ;
Kremic, Emir .
COMPLEX ADAPTIVE SYSTEMS, 2020, 168 :272-278
[38]  
Ubing AA, 2019, INT J ADV COMPUT SC, V10, P252
[39]  
Van Dooremaal B., 2021, INT C AVAILABILITY R
[40]  
Vecliuc D.-D., 2021, ASIAN C INTELLIGENT