• DocumentCode
    2524134
  • Title

    A novel anti-phishing framework based on honeypots

  • Author

    Li, Shujun ; Schmitz, Roland

  • Author_Institution
    Dept. of Comput. & Inf. Sci., Univ. of Konstanz, Konstanz, Germany
  • fYear
    2009
  • fDate
    Sept. 20 2009-Oct. 21 2009
  • Firstpage
    1
  • Lastpage
    13
  • Abstract
    As a powerful anti-phishing tool, honeypots have been widely used by security service providers and financial institutes to collect phishing mails, so that new phishing sites can be earlier detected and quickly shut down. Another popular use of honeypots is to collect useful information about phishers´ activities, which is used to make various kinds of statistics for the purposes of research and forensics. Recently, it has also been proposed to actively feed phishers with honeytokens. In the present paper, we discuss some problems of existing anti-phishing solutions based on honeypots. We propose to overcome these problems by transforming the real e-banking system itself into a honeypot equipped with honeytokens and supported by some other kinds of honeypots. A phishing detector is used to automatically detect suspicious phishers´ attempts of stealing money from victims´ accounts, and then ask for the potential victims´ reconfirmation. This leads to a novel anti-phishing framework based on honeypots. As an indispensable part of the framework, we also propose to use phoneybots, i.e., active honeypots running in virtual machines and mimicking real users´ behavior to access the real e-banking system automatically, in order to submit honeytokens to pharmers and phishing malware. The involvement of phoneybots is crucial to fight against advanced phishing attacks such as pharming and malware-based phishing attacks.
  • Keywords
    banking; computer crime; electronic commerce; anti-phishing framework; e-banking system; honeypots; honeytokens; phishing detector; phishing mails; Clustering algorithms; Computer security; Credit cards; Informatics; Information security; Information technology; Internet; Laboratories; Reliability engineering; Uniform resource locators; honeypot; honeytoken; money mule; online banking; phishing; phoneybot; phoneypot; phoneytoken;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    eCrime Researchers Summit, 2009. eCRIME '09.
  • Conference_Location
    Tacoma, WA
  • Print_ISBN
    978-1-4244-4625-4
  • Type

    conf

  • DOI
    10.1109/ECRIME.2009.5342609
  • Filename
    5342609