The Experts below are selected from a list of 12993 Experts worldwide ranked by ideXlab platform

Jason Hong - One of the best experts on this subject based on the ideXlab platform.

  • ESORICS - A hierarchical adaptive probabilistic approach for zero hour Phish detection
    Computer Security – ESORICS 2010, 2010
    Co-Authors: Guang Xiang, Jason Hong, Bryan A. Pendleton, Carolyn Penstein Rosé
    Abstract:

    Phishing attacks are a significant threat to users of the Internet, causing tremendous economic loss every year. In combating Phish, industry relies heavily on manual verification to achieve a low false positive rate, which, however, tends to be slow in responding to the huge volume of unique Phishing URLs created by toolkits. Our goal here is to combine the best aspects of human verified blacklists and heuristic-based methods, i.e., the low false positive rate of the former and the broad and fast coverage of the latter. To this end, we present the design and evaluation of a hierarchical blacklist-enhanced Phish detection framework. The key insight behind our detection algorithm is to leverage existing human-verified blacklists and apply the shingling technique, a popular near-duplicate detection algorithm used by search engines, to detect Phish in a probabilistic fashion with very high accuracy. To achieve an extremely low false positive rate, we use a filtering module in our layered system, harnessing the power of search engines via information retrieval techniques to correct false positives. Comprehensive experiments over a diverse spectrum of data sources show that our method achieves 0% false positive rate (FP) with a true positive rate (TP) of 67.15% using search-oriented filtering, and 0.03% FP and 73.53% TP without the filtering module. With incremental model building capability via a sliding window mechanism, our approach is able to adapt quickly to new Phishing variants, and is thus more responsive to the evolving attacks.

  • a hierarchical adaptive probabilistic approach for zero hour Phish detection
    European Symposium on Research in Computer Security, 2010
    Co-Authors: Guang Xiang, Jason Hong, Bryan A. Pendleton, Carolyn Penstein Rosé
    Abstract:

    Phishing attacks are a significant threat to users of the Internet, causing tremendous economic loss every year. In combating Phish, industry relies heavily on manual verification to achieve a low false positive rate, which, however, tends to be slow in responding to the huge volume of unique Phishing URLs created by toolkits. Our goal here is to combine the best aspects of human verified blacklists and heuristic-based methods, i.e., the low false positive rate of the former and the broad and fast coverage of the latter. To this end, we present the design and evaluation of a hierarchical blacklist-enhanced Phish detection framework. The key insight behind our detection algorithm is to leverage existing human-verified blacklists and apply the shingling technique, a popular near-duplicate detection algorithm used by search engines, to detect Phish in a probabilistic fashion with very high accuracy. To achieve an extremely low false positive rate, we use a filtering module in our layered system, harnessing the power of search engines via information retrieval techniques to correct false positives. Comprehensive experiments over a diverse spectrum of data sources show that our method achieves 0% false positive rate (FP) with a true positive rate (TP) of 67.15% using search-oriented filtering, and 0.03% FP and 73.53% TP without the filtering module. With incremental model building capability via a sliding window mechanism, our approach is able to adapt quickly to new Phishing variants, and is thus more responsive to the evolving attacks.

  • teaching johnny not to fall for Phish
    ACM Transactions on Internet Technology, 2010
    Co-Authors: Ponnurangam Kumaraguru, Steve Sheng, Lorrie Faith Cranor, Alessandro Acquisti, Jason Hong
    Abstract:

    Phishing attacks, in which criminals lure Internet users to Web sites that spoof legitimate Web sites, are occurring with increasing frequency and are causing considerable harm to victims. While a great deal of effort has been devoted to solving the Phishing problem by prevention and detection of Phishing emails and Phishing Web sites, little research has been done in the area of training users to recognize those attacks. Our research focuses on educating users about Phishing and helping them make better trust decisions. We identified a number of challenges for end-user security education in general and anti-Phishing education in particular: users are not motivated to learn about security; for most users, security is a secondary task; it is difficult to teach people to identify security threats without also increasing their tendency to misjudge nonthreats as threats. Keeping these challenges in mind, we developed an email-based anti-Phishing education system called “PhishGuru” and an online game called “Anti-Phishing Phil” that teaches users how to use cues in URLs to avoid falling for Phishing attacks. We applied learning science instructional principles in the design of PhishGuru and Anti-Phishing Phil. In this article we present the results of PhishGuru and Anti-Phishing Phil user studies that demonstrate the effectiveness of these tools. Our results suggest that, while automated detection systems should be used as the first line of defense against Phishing attacks, user education offers a complementary approach to help people better recognize fraudulent emails and websites.

  • An Empirical Analysis of Phishing Blacklists
    2009
    Co-Authors: Steve Sheng, Gary Warner, Brad Wardman, Lorrie Faith Cranor, Jason Hong, Chengshan Zhang
    Abstract:

    In this paper, we study the eectiveness of Phishing blacklists. We used 191 fresh Phish that were less than 30 minutes old to conduct two tests on eight anti-Phishing toolbars. We found that 63% of the Phishing campaigns in our dataset lasted less than two hours. Blacklists were ineective when protecting users initially, as most of them caught less than 20% of Phish at hour zero. We also found that blacklists were updated at dierent speeds, and varied in coverage, as 47% - 83% of Phish appeared on blacklists 12 hours from the initial test. We found that two tools using heuristics to complement blacklists caught signicantly more Phish initially than those using only blacklists. However, it took a long time for Phish detected by heuristics to appear on blacklists. Finally, we tested the toolbars on a set of 13,458 legitimate URLs for false positives, and did not nd any instance of mislabeling for either blacklists or heuristics. We present these ndings and discuss ways in which anti-Phishing tools can be improved.

  • WWW - A hybrid Phish detection approach by identity discovery and keywords retrieval
    Proceedings of the 18th international conference on World wide web - WWW '09, 2009
    Co-Authors: Guang Xiang, Jason Hong
    Abstract:

    Phishing is a significant security threat to the Internet, which causes tremendous economic loss every year. In this paper, we proposed a novel hybrid Phish detection method based on information extraction (IE) and information retrieval (IR) techniques. The identity-based component of our method detects Phishing webpages by directly discovering the inconsistency between their identity and the identity they are imitating. The keywords-retrieval component utilizes IR algorithms exploiting the power of search engines to identify Phish. Our method requires no training data, no prior knowledge of Phishing signatures and specific implementations, and thus is able to adapt quickly to constantly appearing new Phishing patterns. Comprehensive experiments over a diverse spectrum of data sources with 11449 pages show that both components have a low false positive rate and the stacked approach achieves a true positive rate of 90.06% with a false positive rate of 1.95%.

Renate Reimschuessel - One of the best experts on this subject based on the ideXlab platform.

  • Fish Drug Analysis—Phish-Pharm: 2011 Update
    Aaps Journal, 2012
    Co-Authors: Renate Reimschuessel
    Abstract:

    The searchable fish pharmacokinetics database “Fish Drug Analysis—Phish-Pharm 2011” has been updated and posted online at: http://www.fda.gov/AnimalVeterinary/ScienceResearch/ToolsResources/Phish-Pharm/default.htm. Phish-Pharm was first released in 2005, accompanying an article in the American Association of Pharmaceutical Scientists (AAPS) Journal, “Fish Drug Analysis—Phish-Pharm: A Searchable Database of Pharmacokinetics Data in Fish,” by R. Reimschuessel, L. Stewart, E. Squibb, K. Hirokawa, T. Brady, D. Brooks, B. Shaikh, C. Hodsdon, AAPS Journal. 2005;07(02):E288–E327, article 30 (http://www.aapsj.org/view.asp?art=aapsj070230). The database can be freely downloaded in the form of a Microsoft Office Access file in which multiple parameters can be easily searched, a stand-alone Access Application, or an Excel spreadsheet. In addition, a 508 compliant searchable version for key works is also now available at http://www.accessdata.fda.gov/scripts/fcn/fcnNavigation.cfm?rpt=PhishPharmListing. This information in the database was gathered from over 500 articles, including data from 124 species (95 genera). Data fields include genus, species, water temperatures, the average animal weight, sample types analyzed, drug (or chemical) name, dosage, route of administration, metabolites identified, method of analysis, protein binding, clearance, volume of distribution in a central compartment (Vc) or volume of distribution at steady-state (Vd), and drug half-lives (t½). Additional fields list the citation, authors, title, and Internet links. The document will be periodically updated, and users are invited to submit additional data. Additional updates will be announced as they are available. This database is a valuable resource to investigators of drug metabolism in aquatic species as well as government and private organizations involved in the drug approval process for aquatic species.

  • fish drug analysis Phish pharm 2011 update
    Aaps Journal, 2012
    Co-Authors: Renate Reimschuessel
    Abstract:

    The searchable fish pharmacokinetics database “Fish Drug Analysis—Phish-Pharm 2011” has been updated and posted online at: http://www.fda.gov/AnimalVeterinary/ScienceResearch/ToolsResources/Phish-Pharm/default.htm. Phish-Pharm was first released in 2005, accompanying an article in the American Association of Pharmaceutical Scientists (AAPS) Journal, “Fish Drug Analysis—Phish-Pharm: A Searchable Database of Pharmacokinetics Data in Fish,” by R. Reimschuessel, L. Stewart, E. Squibb, K. Hirokawa, T. Brady, D. Brooks, B. Shaikh, C. Hodsdon, AAPS Journal. 2005;07(02):E288–E327, article 30 (http://www.aapsj.org/view.asp?art=aapsj070230). The database can be freely downloaded in the form of a Microsoft Office Access file in which multiple parameters can be easily searched, a stand-alone Access Application, or an Excel spreadsheet. In addition, a 508 compliant searchable version for key works is also now available at http://www.accessdata.fda.gov/scripts/fcn/fcnNavigation.cfm?rpt=PhishPharmListing. This information in the database was gathered from over 500 articles, including data from 124 species (95 genera). Data fields include genus, species, water temperatures, the average animal weight, sample types analyzed, drug (or chemical) name, dosage, route of administration, metabolites identified, method of analysis, protein binding, clearance, volume of distribution in a central compartment (Vc) or volume of distribution at steady-state (Vd), and drug half-lives (t½). Additional fields list the citation, authors, title, and Internet links. The document will be periodically updated, and users are invited to submit additional data. Additional updates will be announced as they are available. This database is a valuable resource to investigators of drug metabolism in aquatic species as well as government and private organizations involved in the drug approval process for aquatic species.

Melanie Volkamer - One of the best experts on this subject based on the ideXlab platform.

  • User experiences of TORPEDO: TOoltip-powered Phishing email DetectiOn
    Computers & Security, 2017
    Co-Authors: Melanie Volkamer, Karen Renaud, Benjamin Reinheimer, Alexandra Kunz
    Abstract:

    We propose a concept called TORPEDO to improve Phish detection by providing just-in-time and just-in-place trustworthy tooltips. These help people to identify Phish links embedded in emails. TORPEDO's tooltips contain the actual URL with the domain highlighted. Link activation is delayed for a short period, giving the person time to inspect the URL before they click on a link. Furthermore, TORPEDO provides an information diagram to explain Phish detection. We evaluated TORPEDO's effectiveness, as compared to the worst case “status bar” as provided by other Web email interfaces. People using TORPEDO performed significantly better in detecting Phishes and identifying legitimate emails (85.17% versus 43.31% correct answers for Phish). We then carried out a field study with a number of TORPEDO users to explore actual user experiences of TORPEDO. We conclude the paper by reporting on the outcome of this field study and suggest improvements based on the feedback from the field study participants.

  • spot the Phish by checking the pruned url
    Information and Computer Security, 2016
    Co-Authors: Melanie Volkamer, Karen Renaud, Paul Gerber
    Abstract:

    Purpose Phishing is still a very popular and effective security threat, and it takes, on average, more than a day to detect new Phish websites. Protection by purely technical means is hampered by this vulnerability window. During this window, users need to act to protect themselves. To support users in doing so, the paper aims to propose to first make users aware of the need to consult the address bar. Moreover, the authors propose to prune URL displayed in the address bar. The authors report on an evaluation of this proposal. Design/methodology/approach The paper opted for an online study with 411 participants, judging 16 websites – all with authentic design: half with legitimate and half with Phish URLs. The authors applied four popular widely used types of URL manipulation techniques. The authors conducted a within-subject and between-subject study with participants randomly assigned to one of two groups (domain highlighting or pruning). The authors then tested both proposals using a repeated-measures multivariate analysis of variance. Findings The analysis shows a significant improvement in terms of Phish detection after providing the hint to check the address bar. Furthermore, the analysis shows a significant improvement in terms of Phish detection after the hint to check the address bar for uninitiated participants in the pruning group, as compared to those in the highlighting group. Research limitations/implications Because of the chosen research approach, the research results may lack generalisability. Therefore, researchers are encouraged to test the proposed propositions further. Practical implications This paper confirms the efficacy of URL pruning and of prompting users to consult the address bar for Phish detection. Originality/value This paper introduces a classification for URL manipulation techniques used by Phishers. We also provide evidence that drawing people’s attention to the address bar makes them more likely to spot Phish websites, but does not impair their ability to identify authentic websites.

  • torpedo tooltip powered Phishing email detection
    Information Security, 2016
    Co-Authors: Melanie Volkamer, Karen Renaud, Benjamin Reinheimer
    Abstract:

    We propose a concept called TORPEDO to improve Phish detection by providing just-in-time and just-in-place trustworthy tooltips to help people judge links embedded in emails. TORPEDO’s tooltips contain the actual URL with the domain highlighted and delay link activation for a short period, giving the person time to inspect the URL before they click. Furthermore, TORPEDO consists of an information diagram to explain Phish detection. We evaluated TORPEDO in particular with respect to its effectiveness: Compared to the worst case ‘status bar’. as used in Thunderbird and Web email clients. TORPEDO performed significantly better in detecting Phishes and identifying legitimate emails (85.17 % versus 43.31 % correct answers for Phish). A proof of concept implementation is available as a Thunderbird Add-On.

  • SEC - TORPEDO: TOoltip-poweRed Phishing Email DetectiOn
    ICT Systems Security and Privacy Protection, 2016
    Co-Authors: Melanie Volkamer, Karen Renaud, Benjamin Reinheimer
    Abstract:

    We propose a concept called TORPEDO to improve Phish detection by providing just-in-time and just-in-place trustworthy tooltips to help people judge links embedded in emails. TORPEDO’s tooltips contain the actual URL with the domain highlighted and delay link activation for a short period, giving the person time to inspect the URL before they click. Furthermore, TORPEDO consists of an information diagram to explain Phish detection. We evaluated TORPEDO in particular with respect to its effectiveness: Compared to the worst case ‘status bar’. as used in Thunderbird and Web email clients. TORPEDO performed significantly better in detecting Phishes and identifying legitimate emails (85.17 % versus 43.31 % correct answers for Phish). A proof of concept implementation is available as a Thunderbird Add-On.

Benjamin Reinheimer - One of the best experts on this subject based on the ideXlab platform.

  • User experiences of TORPEDO: TOoltip-powered Phishing email DetectiOn
    Computers & Security, 2017
    Co-Authors: Melanie Volkamer, Karen Renaud, Benjamin Reinheimer, Alexandra Kunz
    Abstract:

    We propose a concept called TORPEDO to improve Phish detection by providing just-in-time and just-in-place trustworthy tooltips. These help people to identify Phish links embedded in emails. TORPEDO's tooltips contain the actual URL with the domain highlighted. Link activation is delayed for a short period, giving the person time to inspect the URL before they click on a link. Furthermore, TORPEDO provides an information diagram to explain Phish detection. We evaluated TORPEDO's effectiveness, as compared to the worst case “status bar” as provided by other Web email interfaces. People using TORPEDO performed significantly better in detecting Phishes and identifying legitimate emails (85.17% versus 43.31% correct answers for Phish). We then carried out a field study with a number of TORPEDO users to explore actual user experiences of TORPEDO. We conclude the paper by reporting on the outcome of this field study and suggest improvements based on the feedback from the field study participants.

  • torpedo tooltip powered Phishing email detection
    Information Security, 2016
    Co-Authors: Melanie Volkamer, Karen Renaud, Benjamin Reinheimer
    Abstract:

    We propose a concept called TORPEDO to improve Phish detection by providing just-in-time and just-in-place trustworthy tooltips to help people judge links embedded in emails. TORPEDO’s tooltips contain the actual URL with the domain highlighted and delay link activation for a short period, giving the person time to inspect the URL before they click. Furthermore, TORPEDO consists of an information diagram to explain Phish detection. We evaluated TORPEDO in particular with respect to its effectiveness: Compared to the worst case ‘status bar’. as used in Thunderbird and Web email clients. TORPEDO performed significantly better in detecting Phishes and identifying legitimate emails (85.17 % versus 43.31 % correct answers for Phish). A proof of concept implementation is available as a Thunderbird Add-On.

  • SEC - TORPEDO: TOoltip-poweRed Phishing Email DetectiOn
    ICT Systems Security and Privacy Protection, 2016
    Co-Authors: Melanie Volkamer, Karen Renaud, Benjamin Reinheimer
    Abstract:

    We propose a concept called TORPEDO to improve Phish detection by providing just-in-time and just-in-place trustworthy tooltips to help people judge links embedded in emails. TORPEDO’s tooltips contain the actual URL with the domain highlighted and delay link activation for a short period, giving the person time to inspect the URL before they click. Furthermore, TORPEDO consists of an information diagram to explain Phish detection. We evaluated TORPEDO in particular with respect to its effectiveness: Compared to the worst case ‘status bar’. as used in Thunderbird and Web email clients. TORPEDO performed significantly better in detecting Phishes and identifying legitimate emails (85.17 % versus 43.31 % correct answers for Phish). A proof of concept implementation is available as a Thunderbird Add-On.

Hilarie Orman - One of the best experts on this subject based on the ideXlab platform.

  • The Compleat Story of Phish
    IEEE Internet Computing, 2013
    Co-Authors: Hilarie Orman
    Abstract:

    Deceptive email that leads unwary users to disclose sensitive information on fake websites is the most common form of malware seen by today's users. The technology behind these attacks uses the Internet's weak notion of "place" and the increasing use of websites for financial transactions. Users can protect themselves through precautionary measures, and experts learn to accurately identify malicious email.

  • Towards a Semantics of Phish
    2012 IEEE Symposium on Security and Privacy Workshops, 2012
    Co-Authors: Hilarie Orman
    Abstract:

    Phishing constitutes more than half of all reported security incident son the Internet. The attacks cause users to erroneously trust websites and enter sensitive data because the email notifications and the website look familiar. Our hypothesis is that familiarity can be defined formally using history data from the user's computer, and effective presentation of the data can help users distinguishPhishing messages from trustworthy messages.