Proactive Discovery of Phishing Related Domain Names - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Lecture Notes in Computer Science Année : 2012

Proactive Discovery of Phishing Related Domain Names

Résumé

Phishing is an important security issue to the Internet, which has a significant economic impact. The main solution to counteract this threat is currently reactive blacklisting; however, as phishing attacks are mainly performed over short periods of time, reactive methods are too slow. As a result, new approaches to early identify malicious websites are needed. In this paper a new proactive discovery of phishing related domain names is introduced. We mainly focus on the automated detection of possible domain registrations for malicious activities. We leverage techniques coming from natural language modelling in order to build pro-active blacklists. The entries in this list are built using language models and vocabularies encountered in phishing related activities - "secure", "banking", brand names, etc. Once a pro-active blacklist is created, ongoing and daily monitoring of only these domains can lead to the efficient detection of phishing web sites.
Fichier principal
Vignette du fichier
proactiveDiscoveryPhishing.pdf (599.31 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00748808 , version 1 (06-11-2012)

Identifiants

Citer

Samuel Marchal, Jérôme François, Radu State, Thomas Engel. Proactive Discovery of Phishing Related Domain Names. Research in Attacks, Intrusions, and Defenses, Sep 2012, Amsterdam, Netherlands. pp.190-209, ⟨10.1007/978-3-642-33338-5_10⟩. ⟨hal-00748808⟩
93 Consultations
1380 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More