The Experts below are selected from a list of 9489 Experts worldwide ranked by ideXlab platform

Lorrie Cranor - One of the best experts on this subject based on the ideXlab platform.

  • Cantina+: A feature-rich machine learning framework for detecting phishing web sites
    2014
    Co-Authors: Guang Xiang, Jason Hong, Carolyn P. Rose, Lorrie Cranor
    Abstract:

    Phishing is a plague in cyberspace. Typically, phish detection methods either use humanverified URL blacklists or exploit webpage features via machine learning techniques. However, the former is frail in terms of new phish, and the latter suffers from the scarcity of effective features and the high false positive rate (FP). To alleviate those problems, we propose a layered anti-phishing solution that aims at 1) exploiting the expressiveness of a rich set of features with machine learning to achieve a high true positive rate (TP) on novel phish, and 2) limiting the FP to a low level via filtering algorithms. Specifically, we proposed CANTINA+, the most comprehensive feature-based approach in the literature including eight novel features, which exploits the HTML Document Object Model (DOM), search engines and third party services with machine learning techniques to detect phish. Moreover, we designed two filters to help reduce FP and achieve runtime speedup. The first is a near-duplicate phish detector that uses hashing to catch highly similar phish. The second is a login form filter, which directly classifies webpages with no identified login form as legitimate. We extensively evaluated CANTINA+ with two methods on a diverse spectrum of corpora with 8118 phish and 4883 legitimate webpages. In the randomized evaluation, CANTINA+ achieved over 90 % TP on unique testing phish and over 99 % TP on near-duplicate testing phish, and about 0.4 % FP with 10 % training phish. In the time-based evaluation, CANTINA+ achieved over 87% TP on unique testing phish, about 95 % TP on near-duplicate testing phish, and about 1 % FP under 20 % training phish with a two-week sliding window. Capable of achieving 0.4 % FP and over 90 % TP, our CANTINA+ has been demonstrated to be a competitive anti-phishing solution

  • cantina a feature rich machine learning framework for detecting phishing web sites
    ACM Transactions on Information and System Security, 2011
    Co-Authors: Guang Xiang, Jason Hong, Carolyn P. Rose, Lorrie Cranor
    Abstract:

    Phishing is a plague in cyberspace. Typically, phish detection methods either use human-verified URL blacklists or exploit Web page features via machine learning techniques. However, the former is frail in terms of new phish, and the latter suffers from the scarcity of effective features and the high false positive rate (FP). To alleviate those problems, we propose a layered anti-phishing solution that aims at (1) exploiting the expressiveness of a rich set of features with machine learning to achieve a high true positive rate (TP) on novel phish, and (2) limiting the FP to a low level via filtering algorithms. Specifically, we proposed CANTINA+, the most comprehensive feature-based approach in the literature including eight novel features, which exploits the HTML Document Object Model (DOM), search engines and third party services with machine learning techniques to detect phish. Moreover, we designed two filters to help reduce FP and achieve runtime speedup. The first is a near-duplicate phish detector that uses hashing to catch highly similar phish. The second is a login form filter, which directly classifies Web pages with no identified login form as legitimate. We extensively evaluated CANTINA+ with two methods on a diverse spectrum of corpora with 8118 phish and 4883 legitimate Web pages. In the randomized evaluation, CANTINA+ achieved over 92p TP on unique testing phish and over 99p TP on near-duplicate testing phish, and about 0.4p FP with 10p training phish. In the time-based evaluation, CANTINA+ also achieved over 92p TP on unique testing phish, over 99p TP on near-duplicate testing phish, and about 1.4p FP under 20p training phish with a two-week sliding window. Capable of achieving 0.4p FP and over 92p TP, our CANTINA+ has been demonstrated to be a competitive anti-phishing solution.

Guang Xiang - One of the best experts on this subject based on the ideXlab platform.

  • Cantina+: A feature-rich machine learning framework for detecting phishing web sites
    2014
    Co-Authors: Guang Xiang, Jason Hong, Carolyn P. Rose, Lorrie Cranor
    Abstract:

    Phishing is a plague in cyberspace. Typically, phish detection methods either use humanverified URL blacklists or exploit webpage features via machine learning techniques. However, the former is frail in terms of new phish, and the latter suffers from the scarcity of effective features and the high false positive rate (FP). To alleviate those problems, we propose a layered anti-phishing solution that aims at 1) exploiting the expressiveness of a rich set of features with machine learning to achieve a high true positive rate (TP) on novel phish, and 2) limiting the FP to a low level via filtering algorithms. Specifically, we proposed CANTINA+, the most comprehensive feature-based approach in the literature including eight novel features, which exploits the HTML Document Object Model (DOM), search engines and third party services with machine learning techniques to detect phish. Moreover, we designed two filters to help reduce FP and achieve runtime speedup. The first is a near-duplicate phish detector that uses hashing to catch highly similar phish. The second is a login form filter, which directly classifies webpages with no identified login form as legitimate. We extensively evaluated CANTINA+ with two methods on a diverse spectrum of corpora with 8118 phish and 4883 legitimate webpages. In the randomized evaluation, CANTINA+ achieved over 90 % TP on unique testing phish and over 99 % TP on near-duplicate testing phish, and about 0.4 % FP with 10 % training phish. In the time-based evaluation, CANTINA+ achieved over 87% TP on unique testing phish, about 95 % TP on near-duplicate testing phish, and about 1 % FP under 20 % training phish with a two-week sliding window. Capable of achieving 0.4 % FP and over 90 % TP, our CANTINA+ has been demonstrated to be a competitive anti-phishing solution

  • cantina a feature rich machine learning framework for detecting phishing web sites
    ACM Transactions on Information and System Security, 2011
    Co-Authors: Guang Xiang, Jason Hong, Carolyn P. Rose, Lorrie Cranor
    Abstract:

    Phishing is a plague in cyberspace. Typically, phish detection methods either use human-verified URL blacklists or exploit Web page features via machine learning techniques. However, the former is frail in terms of new phish, and the latter suffers from the scarcity of effective features and the high false positive rate (FP). To alleviate those problems, we propose a layered anti-phishing solution that aims at (1) exploiting the expressiveness of a rich set of features with machine learning to achieve a high true positive rate (TP) on novel phish, and (2) limiting the FP to a low level via filtering algorithms. Specifically, we proposed CANTINA+, the most comprehensive feature-based approach in the literature including eight novel features, which exploits the HTML Document Object Model (DOM), search engines and third party services with machine learning techniques to detect phish. Moreover, we designed two filters to help reduce FP and achieve runtime speedup. The first is a near-duplicate phish detector that uses hashing to catch highly similar phish. The second is a login form filter, which directly classifies Web pages with no identified login form as legitimate. We extensively evaluated CANTINA+ with two methods on a diverse spectrum of corpora with 8118 phish and 4883 legitimate Web pages. In the randomized evaluation, CANTINA+ achieved over 92p TP on unique testing phish and over 99p TP on near-duplicate testing phish, and about 0.4p FP with 10p training phish. In the time-based evaluation, CANTINA+ also achieved over 92p TP on unique testing phish, over 99p TP on near-duplicate testing phish, and about 1.4p FP under 20p training phish with a two-week sliding window. Capable of achieving 0.4p FP and over 92p TP, our CANTINA+ has been demonstrated to be a competitive anti-phishing solution.

Jason Hong - One of the best experts on this subject based on the ideXlab platform.

  • Cantina+: A feature-rich machine learning framework for detecting phishing web sites
    2014
    Co-Authors: Guang Xiang, Jason Hong, Carolyn P. Rose, Lorrie Cranor
    Abstract:

    Phishing is a plague in cyberspace. Typically, phish detection methods either use humanverified URL blacklists or exploit webpage features via machine learning techniques. However, the former is frail in terms of new phish, and the latter suffers from the scarcity of effective features and the high false positive rate (FP). To alleviate those problems, we propose a layered anti-phishing solution that aims at 1) exploiting the expressiveness of a rich set of features with machine learning to achieve a high true positive rate (TP) on novel phish, and 2) limiting the FP to a low level via filtering algorithms. Specifically, we proposed CANTINA+, the most comprehensive feature-based approach in the literature including eight novel features, which exploits the HTML Document Object Model (DOM), search engines and third party services with machine learning techniques to detect phish. Moreover, we designed two filters to help reduce FP and achieve runtime speedup. The first is a near-duplicate phish detector that uses hashing to catch highly similar phish. The second is a login form filter, which directly classifies webpages with no identified login form as legitimate. We extensively evaluated CANTINA+ with two methods on a diverse spectrum of corpora with 8118 phish and 4883 legitimate webpages. In the randomized evaluation, CANTINA+ achieved over 90 % TP on unique testing phish and over 99 % TP on near-duplicate testing phish, and about 0.4 % FP with 10 % training phish. In the time-based evaluation, CANTINA+ achieved over 87% TP on unique testing phish, about 95 % TP on near-duplicate testing phish, and about 1 % FP under 20 % training phish with a two-week sliding window. Capable of achieving 0.4 % FP and over 90 % TP, our CANTINA+ has been demonstrated to be a competitive anti-phishing solution

  • cantina a feature rich machine learning framework for detecting phishing web sites
    ACM Transactions on Information and System Security, 2011
    Co-Authors: Guang Xiang, Jason Hong, Carolyn P. Rose, Lorrie Cranor
    Abstract:

    Phishing is a plague in cyberspace. Typically, phish detection methods either use human-verified URL blacklists or exploit Web page features via machine learning techniques. However, the former is frail in terms of new phish, and the latter suffers from the scarcity of effective features and the high false positive rate (FP). To alleviate those problems, we propose a layered anti-phishing solution that aims at (1) exploiting the expressiveness of a rich set of features with machine learning to achieve a high true positive rate (TP) on novel phish, and (2) limiting the FP to a low level via filtering algorithms. Specifically, we proposed CANTINA+, the most comprehensive feature-based approach in the literature including eight novel features, which exploits the HTML Document Object Model (DOM), search engines and third party services with machine learning techniques to detect phish. Moreover, we designed two filters to help reduce FP and achieve runtime speedup. The first is a near-duplicate phish detector that uses hashing to catch highly similar phish. The second is a login form filter, which directly classifies Web pages with no identified login form as legitimate. We extensively evaluated CANTINA+ with two methods on a diverse spectrum of corpora with 8118 phish and 4883 legitimate Web pages. In the randomized evaluation, CANTINA+ achieved over 92p TP on unique testing phish and over 99p TP on near-duplicate testing phish, and about 0.4p FP with 10p training phish. In the time-based evaluation, CANTINA+ also achieved over 92p TP on unique testing phish, over 99p TP on near-duplicate testing phish, and about 1.4p FP under 20p training phish with a two-week sliding window. Capable of achieving 0.4p FP and over 92p TP, our CANTINA+ has been demonstrated to be a competitive anti-phishing solution.

Carolyn P. Rose - One of the best experts on this subject based on the ideXlab platform.

  • Cantina+: A feature-rich machine learning framework for detecting phishing web sites
    2014
    Co-Authors: Guang Xiang, Jason Hong, Carolyn P. Rose, Lorrie Cranor
    Abstract:

    Phishing is a plague in cyberspace. Typically, phish detection methods either use humanverified URL blacklists or exploit webpage features via machine learning techniques. However, the former is frail in terms of new phish, and the latter suffers from the scarcity of effective features and the high false positive rate (FP). To alleviate those problems, we propose a layered anti-phishing solution that aims at 1) exploiting the expressiveness of a rich set of features with machine learning to achieve a high true positive rate (TP) on novel phish, and 2) limiting the FP to a low level via filtering algorithms. Specifically, we proposed CANTINA+, the most comprehensive feature-based approach in the literature including eight novel features, which exploits the HTML Document Object Model (DOM), search engines and third party services with machine learning techniques to detect phish. Moreover, we designed two filters to help reduce FP and achieve runtime speedup. The first is a near-duplicate phish detector that uses hashing to catch highly similar phish. The second is a login form filter, which directly classifies webpages with no identified login form as legitimate. We extensively evaluated CANTINA+ with two methods on a diverse spectrum of corpora with 8118 phish and 4883 legitimate webpages. In the randomized evaluation, CANTINA+ achieved over 90 % TP on unique testing phish and over 99 % TP on near-duplicate testing phish, and about 0.4 % FP with 10 % training phish. In the time-based evaluation, CANTINA+ achieved over 87% TP on unique testing phish, about 95 % TP on near-duplicate testing phish, and about 1 % FP under 20 % training phish with a two-week sliding window. Capable of achieving 0.4 % FP and over 90 % TP, our CANTINA+ has been demonstrated to be a competitive anti-phishing solution

  • cantina a feature rich machine learning framework for detecting phishing web sites
    ACM Transactions on Information and System Security, 2011
    Co-Authors: Guang Xiang, Jason Hong, Carolyn P. Rose, Lorrie Cranor
    Abstract:

    Phishing is a plague in cyberspace. Typically, phish detection methods either use human-verified URL blacklists or exploit Web page features via machine learning techniques. However, the former is frail in terms of new phish, and the latter suffers from the scarcity of effective features and the high false positive rate (FP). To alleviate those problems, we propose a layered anti-phishing solution that aims at (1) exploiting the expressiveness of a rich set of features with machine learning to achieve a high true positive rate (TP) on novel phish, and (2) limiting the FP to a low level via filtering algorithms. Specifically, we proposed CANTINA+, the most comprehensive feature-based approach in the literature including eight novel features, which exploits the HTML Document Object Model (DOM), search engines and third party services with machine learning techniques to detect phish. Moreover, we designed two filters to help reduce FP and achieve runtime speedup. The first is a near-duplicate phish detector that uses hashing to catch highly similar phish. The second is a login form filter, which directly classifies Web pages with no identified login form as legitimate. We extensively evaluated CANTINA+ with two methods on a diverse spectrum of corpora with 8118 phish and 4883 legitimate Web pages. In the randomized evaluation, CANTINA+ achieved over 92p TP on unique testing phish and over 99p TP on near-duplicate testing phish, and about 0.4p FP with 10p training phish. In the time-based evaluation, CANTINA+ also achieved over 92p TP on unique testing phish, over 99p TP on near-duplicate testing phish, and about 1.4p FP under 20p training phish with a two-week sliding window. Capable of achieving 0.4p FP and over 92p TP, our CANTINA+ has been demonstrated to be a competitive anti-phishing solution.

Christian Hammer - One of the best experts on this subject based on the ideXlab platform.

  • information flow control for event handling and the dom in web browsers
    IEEE Computer Security Foundations Symposium, 2015
    Co-Authors: Vineet Rajani, Abhishek Bichhawat, Deepak Garg, Christian Hammer
    Abstract:

    Web browsers routinely handle private information. Owing to a lax security Model, browsers and JavaScript in particular, are easy targets for leaking sensitive data. Prior work has extensively studied information flow control (IFC) as a mechanism for securing browsers. However, two central aspects of web browsers -- the Document Object Model (DOM) and the event handling mechanism -- have so far evaded thorough scrutiny in the context of IFC. This paper advances the state-of-the-art in this regard. Based on standard specifications and the code of an actual browser engine, we build formal Models of both the DOM (up to Level 3) and the event handling loop of a typical browser, enhance the Models with fine-grained taints and checks for IFC, prove our enhancements sound and test our ideas through an instrumentation of WebKit, an in-production browser engine. In doing so, we observe several channels for information leak that arise due to subtleties of the event loop and its interaction with the DOM.