• DocumentCode
    3390629
  • Title

    Visual similarity-based phishing detection without victim site information

  • Author

    Hara, Masanori ; Yamada, Akira ; Miyake, Yutaka

  • Author_Institution
    Network Security Lab. of KDDI R&D Labs. Inc., Chiba
  • fYear
    2009
  • fDate
    March 30 2009-April 2 2009
  • Firstpage
    30
  • Lastpage
    36
  • Abstract
    Phishing attacks, which steal users´ account information by fake Websites, have become a serious problem on theInternet. There are two major approaches in phishing detection: the blacklist- and the heuristics-based approach. Heuristics-based approaches employ common characteristics of phishing sites such as distinctive keywords used in Web pages or URLs in order to detect new phishing sites that are not yet listed in blacklists. However, these kinds of heuristics can be easily circumvented by phishers once their mechanism is revealed. In order to overcome this weakness, visual similarity-based detection techniques have been proposed. Because phishing sites have to mimic victim sites, visual similarity between phishing sites and their victim sites is supposed to be an inherent and not easily concealable characteristic. However, these techniques require images of real victim sites for detection. In this paper, we propose a phishing detection mechanism based on visual similarity among phishing sites that mimic the same victim site. Surprisingly, just by analyzing visual similarity among Web pages without a priori knowledge, our method automatically extracts 224 distinct Web page layouts mimicked by 2,262 phishing sites and achieves a detection rate of over 80% while keeping the false-positive rate to 17.5%. We also find that the false-positive rate can be reduced.
  • Keywords
    Internet; Web sites; security of data; Internet; Web pages; fake Websites; phishing attacks; visual similarity-based phishing detection; Authentication; Electronic mail; Image databases; Internet; Proposals; Software maintenance; Uniform resource locators; Visual databases; Web pages;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence in Cyber Security, 2009. CICS '09. IEEE Symposium on
  • Conference_Location
    Nashville, TN
  • Print_ISBN
    978-1-4244-2769-7
  • Type

    conf

  • DOI
    10.1109/CICYBS.2009.4925087
  • Filename
    4925087