The Experts below are selected from a list of 1191 Experts worldwide ranked by ideXlab platform
Bruhadeshwar Bezawada - One of the best experts on this subject based on the ideXlab platform.
-
DBSec - Adversarial Sampling Attacks Against Phishing Detection
Data and Applications Security and Privacy XXXIII, 2019Co-Authors: Hossein Shirazi, Bruhadeshwar Bezawada, Charles W. AndersonAbstract:Phishing websites trick users into believing that they are interacting with a legitimate website, and thereby, capture sensitive information, such as user names, passwords, credit card numbers and other personal information. Machine learning appears to be a promising technique for distinguishing between Phishing websites and legitimate ones. However, machine learning approaches are susceptible to adversarial learning techniques, which attempt to degrade the accuracy of a trained classifier model. In this work, we investigate the robustness of machine learning based Phishing Detection in the face of adversarial learning techniques. We propose a simple but effective approach to simulate attacks by generating adversarial samples through direct feature manipulation. We assume that the attacker has limited knowledge of the features, the learning models, and the datasets used for training. We conducted experiments on four publicly available datasets on the Internet. Our experiments reveal that the Phishing Detection mechanisms are vulnerable to adversarial learning techniques. Specifically, the identification rate for Phishing websites dropped to 70% by manipulating a single feature. When four features were manipulated, the identification rate dropped to zero percent. This result means that, any Phishing sample, which would have been detected correctly by a classifier model, can bypass the classifier by changing at most four feature values; a simple effort for an attacker for such a big reward. We define the concept of vulnerability level for each dataset that measures the number of features that can be manipulated and the cost for each manipulation. Such a metric will allow us to compare between multiple defense models.
-
kn0w thy doma1n name unbiased Phishing Detection using domain name based features
Symposium on Access Control Models and Technologies, 2018Co-Authors: Hossein Shirazi, Bruhadeshwar BezawadaAbstract:Phishing websites remain a persistent security threat. Thus far, machine learning approaches appear to have the best potential as defenses. But, there are two main concerns with existing machine learning approaches for Phishing Detection. The first is the large number of training features used and the lack of validating arguments for these feature choices. The second concern is the type of datasets used in the literature that are inadvertently biased with respect to the features based on the website URL or content. To address these concerns, we put forward the intuition that the domain name of Phishing websites is the tell-tale sign of Phishing and holds the key to successful Phishing Detection. Accordingly, we design features that model the relationships, visual as well as statistical, of the domain name to the key elements of a Phishing website, which are used to snare the end-users. The main value of our feature design is that, to bypass Detection, an attacker will find it very difficult to tamper with the visual content of the Phishing website without arousing the suspicion of the end user. Our feature set ensures that there is minimal or no bias with respect to a dataset. Our learning model trains with only seven features and achieves a true positive rate of 98% and a classification accuracy of 97%, on sample dataset. Compared to the state-of-the-art work, our per data instance classification is 4 times faster for legitimate websites and 10 times faster for Phishing websites. Importantly, we demonstrate the shortcomings of using features based on URLs as they are likely to be biased towards specific datasets. We show the robustness of our learning algorithm by testing on unknown live Phishing URLs and achieve a high Detection accuracy of $99.7%$.
-
SACMAT - "Kn0w Thy Doma1n Name" : Unbiased Phishing Detection Using Domain Name Based Features
Proceedings of the 23nd ACM on Symposium on Access Control Models and Technologies, 2018Co-Authors: Hossein Shirazi, Bruhadeshwar BezawadaAbstract:Phishing websites remain a persistent security threat. Thus far, machine learning approaches appear to have the best potential as defenses. But, there are two main concerns with existing machine learning approaches for Phishing Detection. The first is the large number of training features used and the lack of validating arguments for these feature choices. The second concern is the type of datasets used in the literature that are inadvertently biased with respect to the features based on the website URL or content. To address these concerns, we put forward the intuition that the domain name of Phishing websites is the tell-tale sign of Phishing and holds the key to successful Phishing Detection. Accordingly, we design features that model the relationships, visual as well as statistical, of the domain name to the key elements of a Phishing website, which are used to snare the end-users. The main value of our feature design is that, to bypass Detection, an attacker will find it very difficult to tamper with the visual content of the Phishing website without arousing the suspicion of the end user. Our feature set ensures that there is minimal or no bias with respect to a dataset. Our learning model trains with only seven features and achieves a true positive rate of 98% and a classification accuracy of 97%, on sample dataset. Compared to the state-of-the-art work, our per data instance classification is 4 times faster for legitimate websites and 10 times faster for Phishing websites. Importantly, we demonstrate the shortcomings of using features based on URLs as they are likely to be biased towards specific datasets. We show the robustness of our learning algorithm by testing on unknown live Phishing URLs and achieve a high Detection accuracy of $99.7%$.
M. A. Hossain - One of the best experts on this subject based on the ideXlab platform.
-
Deep Learning with Convolutional Neural Network and Long Short-Term Memory for Phishing Detection
2019 13th International Conference on Software Knowledge Information Management and Applications (SKIMA), 2019Co-Authors: M. A. Adebowale, K. T. Lwin, M. A. HossainAbstract:Phishers sometimes exploit users' trust of a known website's appearance by using a similar page that looks like the legitimate site. In recent times, researchers have tried to identify and classify the issues that can contribute to the Detection of Phishing websites. This study focuses on design and development of a deep learning based Phishing Detection solution that leverages the Universal Resource Locator and website content such as images and frame elements. A Convolutional Neural Network (CNN) and the Long Short-Term Memory (LSTM) algorithm were used to build a classification model. The experimental results showed that the proposed model achieved an accuracy rate of 93.28%.
-
intelligent Phishing Detection and protection scheme for online transactions
Expert Systems With Applications, 2013Co-Authors: Phoebe Barraclough, M. A. Hossain, Muhammad Atif Tahir, Graham Sexton, Nauman AslamAbstract:Phishing is an instance of social engineering techniques used to deceive users into giving their sensitive information using an illegitimate website that looks and feels exactly like the target organization website. Most Phishing Detection approaches utilizes Uniform Resource Locator (URL) blacklists or Phishing website features combined with machine learning techniques to combat Phishing. Despite the existing approaches that utilize URL blacklists, they cannot generalize well with new Phishing attacks due to human weakness in verifying blacklists, while the existing feature-based methods suffer high false positive rates and insufficient Phishing features. As a result, this leads to an inadequacy in the online transactions. To solve this problem robustly, the proposed study introduces new inputs (Legitimate site rules, User-behavior profile, PhishTank, User-specific sites, Pop-Ups from emails) which were not considered previously in a single protection platform. The idea is to utilize a Neuro-Fuzzy Scheme with 5 inputs to detect Phishing sites with high accuracy in real-time. In this study, 2-Fold cross-validation is applied for training and testing the proposed model. A total of 288 features with 5 inputs were used and has so far achieved the best performance as compared to all previously reported results in the field.
Hossein Shirazi - One of the best experts on this subject based on the ideXlab platform.
-
DBSec - Adversarial Sampling Attacks Against Phishing Detection
Data and Applications Security and Privacy XXXIII, 2019Co-Authors: Hossein Shirazi, Bruhadeshwar Bezawada, Charles W. AndersonAbstract:Phishing websites trick users into believing that they are interacting with a legitimate website, and thereby, capture sensitive information, such as user names, passwords, credit card numbers and other personal information. Machine learning appears to be a promising technique for distinguishing between Phishing websites and legitimate ones. However, machine learning approaches are susceptible to adversarial learning techniques, which attempt to degrade the accuracy of a trained classifier model. In this work, we investigate the robustness of machine learning based Phishing Detection in the face of adversarial learning techniques. We propose a simple but effective approach to simulate attacks by generating adversarial samples through direct feature manipulation. We assume that the attacker has limited knowledge of the features, the learning models, and the datasets used for training. We conducted experiments on four publicly available datasets on the Internet. Our experiments reveal that the Phishing Detection mechanisms are vulnerable to adversarial learning techniques. Specifically, the identification rate for Phishing websites dropped to 70% by manipulating a single feature. When four features were manipulated, the identification rate dropped to zero percent. This result means that, any Phishing sample, which would have been detected correctly by a classifier model, can bypass the classifier by changing at most four feature values; a simple effort for an attacker for such a big reward. We define the concept of vulnerability level for each dataset that measures the number of features that can be manipulated and the cost for each manipulation. Such a metric will allow us to compare between multiple defense models.
-
kn0w thy doma1n name unbiased Phishing Detection using domain name based features
Symposium on Access Control Models and Technologies, 2018Co-Authors: Hossein Shirazi, Bruhadeshwar BezawadaAbstract:Phishing websites remain a persistent security threat. Thus far, machine learning approaches appear to have the best potential as defenses. But, there are two main concerns with existing machine learning approaches for Phishing Detection. The first is the large number of training features used and the lack of validating arguments for these feature choices. The second concern is the type of datasets used in the literature that are inadvertently biased with respect to the features based on the website URL or content. To address these concerns, we put forward the intuition that the domain name of Phishing websites is the tell-tale sign of Phishing and holds the key to successful Phishing Detection. Accordingly, we design features that model the relationships, visual as well as statistical, of the domain name to the key elements of a Phishing website, which are used to snare the end-users. The main value of our feature design is that, to bypass Detection, an attacker will find it very difficult to tamper with the visual content of the Phishing website without arousing the suspicion of the end user. Our feature set ensures that there is minimal or no bias with respect to a dataset. Our learning model trains with only seven features and achieves a true positive rate of 98% and a classification accuracy of 97%, on sample dataset. Compared to the state-of-the-art work, our per data instance classification is 4 times faster for legitimate websites and 10 times faster for Phishing websites. Importantly, we demonstrate the shortcomings of using features based on URLs as they are likely to be biased towards specific datasets. We show the robustness of our learning algorithm by testing on unknown live Phishing URLs and achieve a high Detection accuracy of $99.7%$.
-
SACMAT - "Kn0w Thy Doma1n Name" : Unbiased Phishing Detection Using Domain Name Based Features
Proceedings of the 23nd ACM on Symposium on Access Control Models and Technologies, 2018Co-Authors: Hossein Shirazi, Bruhadeshwar BezawadaAbstract:Phishing websites remain a persistent security threat. Thus far, machine learning approaches appear to have the best potential as defenses. But, there are two main concerns with existing machine learning approaches for Phishing Detection. The first is the large number of training features used and the lack of validating arguments for these feature choices. The second concern is the type of datasets used in the literature that are inadvertently biased with respect to the features based on the website URL or content. To address these concerns, we put forward the intuition that the domain name of Phishing websites is the tell-tale sign of Phishing and holds the key to successful Phishing Detection. Accordingly, we design features that model the relationships, visual as well as statistical, of the domain name to the key elements of a Phishing website, which are used to snare the end-users. The main value of our feature design is that, to bypass Detection, an attacker will find it very difficult to tamper with the visual content of the Phishing website without arousing the suspicion of the end user. Our feature set ensures that there is minimal or no bias with respect to a dataset. Our learning model trains with only seven features and achieves a true positive rate of 98% and a classification accuracy of 97%, on sample dataset. Compared to the state-of-the-art work, our per data instance classification is 4 times faster for legitimate websites and 10 times faster for Phishing websites. Importantly, we demonstrate the shortcomings of using features based on URLs as they are likely to be biased towards specific datasets. We show the robustness of our learning algorithm by testing on unknown live Phishing URLs and achieve a high Detection accuracy of $99.7%$.
Mohammed Alamgir Hossain - One of the best experts on this subject based on the ideXlab platform.
-
Intelligent web-Phishing Detection and protection scheme using integrated features of Images, frames and text
Expert Systems With Applications, 2020Co-Authors: Moruf A. Adebowale, Khin T. Lwin, Erika Sanchez, Mohammed Alamgir HossainAbstract:Abstract A Phishing attack is one of the most significant problems faced by online users because of its enormous effect on the online activities performed. In recent years, Phishing attacks continue to escalate in frequency, severity and impact. Several solutions, using various methodologies, have been proposed in the literature to counter the web-Phishing threats. Notwithstanding, the existing technology cannot detect the new Phishing attacks accurately due to the insufficient integration of features of the text, image and frame in the evaluation process. The use of related features of images, frames and text of legitimate and non-legitimate websites and associated artificial intelligence algorithms to develop an integrated method to address these together. This paper presents an Adaptive Neuro-Fuzzy Inference System (ANFIS) based robust scheme using the integrated features of the text, images and frames for web-Phishing Detection and protection. The proposed solution achieves 98.3% accuracies. To our best knowledge, this is the first work that considers the best-integrated text, image and frame feature based solution for Phishing Detection scheme.
-
SKIMA - Deep Learning with Convolutional Neural Network and Long Short-Term Memory for Phishing Detection
2019 13th International Conference on Software Knowledge Information Management and Applications (SKIMA), 2019Co-Authors: M. A. Adebowale, Khin T. Lwin, Mohammed Alamgir HossainAbstract:Phishers sometimes exploit users’ trust of a known website’s appearance by using a similar page that looks like the legitimate site. In recent times, researchers have tried to identify and classify the issues that can contribute to the Detection of Phishing websites. This study focuses on design and development of a deep learning based Phishing Detection solution that leverages the Universal Resource Locator and website content such as images and frame elements. A Convolutional Neural Network (CNN) and the Long Short-Term Memory (LSTM) algorithm were used to build a classification model. The experimental results showed that the proposed model achieved an accuracy rate of 93.28%.
Arnon Rungsawang - One of the best experts on this subject based on the ideXlab platform.
-
iiWAS - Web Phishing Detection using classifier ensemble
Proceedings of the 12th International Conference on Information Integration and Web-based Applications & Services - iiWAS '10, 2010Co-Authors: Nuttapong Sanglerdsinlapachai, Arnon RungsawangAbstract:This research adapts and develops various methods in Artificial Intelligent (A.I) field to improve web Phishing Detection. Based on the features from Carnegie Mellon Anti-Phishing and Network Analysis Tool (CANTINA), we add, modify or reduce features in case of using to train a machine learning method. We also add our developed features called homepage similarity features to the machine. Moreover, we applied the classifier ensemble concept to the study. After training with 500 Phishing web pages and 500 non-Phishing web pages, the experiments on 1,500 pages per each class showed that our proposed methodology could boost accuracy up to approximately 30% from traditional heuristic method's results.
-
WKDD - Using Domain Top-page Similarity Feature in Machine Learning-Based Web Phishing Detection
2010 Third International Conference on Knowledge Discovery and Data Mining, 2010Co-Authors: Nuttapong Sanglerdsinlapachai, Arnon RungsawangAbstract:This paper presents a study on using a concept feature to detect web Phishing problem. Following the features introduced in Carnegie Mellon Anti-Phishing and Network Analysis Tool (CANTINA), we applied additional domain top-page similarity feature to a machine learning based Phishing Detection system. We preliminarily experimented with a small set of 200 web data, consisting of 100 Phishing webs and another 100 non-Phishing webs. The evaluation result in terms of f-measure was up to 0.9250, with 7.50% of error rate.
-
Using Domain Top-page Similarity Feature in Machine Learning-Based Web Phishing Detection
2010 Third International Conference on Knowledge Discovery and Data Mining, 2010Co-Authors: Nuttapong Sanglerdsinlapachai, Arnon RungsawangAbstract:This paper presents a study on using a concept feature to detect web Phishing problem. Following the features introduced in Carnegie Mellon Anti-Phishing and Network Analysis Tool (CANTINA), we applied additional domain top-page similarity feature to a machine learning based Phishing Detection system. We preliminarily experimented with a small set of 200 web data, consisting of 100 Phishing webs and another 100 non-Phishing webs. The evaluation result in terms of f-measure was up to 0.9250, with 7.50% of error rate.