The Experts below are selected from a list of 192 Experts worldwide ranked by ideXlab platform

M Daniluk - One of the best experts on this subject based on the ideXlab platform.

  • Phishwish: a simple and stateless Phishing Filter
    SECURITY AND COMMUNICATION NETWORKS, 2009
    Co-Authors: D. L. Cook, Vijay K Gurbani, M Daniluk
    Abstract:

    We define Phishing as the practice of directing unsuspecting users to fraudulent websites with the intent of obtaining personal information to be used for illicit purpose by a spammer. We introduce a new anti-Phishing Filter, phishwish, that has a number of advantages over existing Phishing Filters: it does not need to be trained, as is the case with Bayesian Filters, nor does it consult centralized white or blacklists to determine whether an email is suspect. Phishwish uses a set of only 11 rules to determine the veracity of an incoming email; the results can be used to quarantine the email or to alert the user. We compare the performance of phishwish to {SpamAssassin}, a popular open source Filter, as well as the Google Phishing Filters accessed from the Firefox browser. Our results indicate that phishwish outperforms existing Filters in identifying Phishing emails, even identifying those originated by the 'rock phish' gang, and that it aids in detection of zero-day attacks that were not caught by existing Filters. Copyright (C) 2008 John Wiley & Sons, Ltd.

  • Phishwish: A stateless Phishing Filter using minimal rules
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2008
    Co-Authors: D. L. Cook, Vijay K Gurbani, M Daniluk
    Abstract:

    We introduce phishwish, a Phishing Filter that offers advan- tages over existing Filters: It does not need any training and does not consult centralized white or black lists. Furthermore, it is simple to con- figure, requiring only 11 rules to determine the veracity of an incoming email.We compare the performance of phishwish to SpamAssassin and to Google’s browser-based Phishing Filter. Our results indicate that phish- wish outperforms these Filters and identifies zero days attacks that went undetected by existing Filters.

  • Financial Cryptography - Phishwish: A Stateless Phishing Filter Using Minimal Rules
    Financial Cryptography and Data Security, 1
    Co-Authors: D. L. Cook, Vijay K Gurbani, M Daniluk
    Abstract:

    We introduce phishwish, a Phishing Filter that offers advantages over existing Filters: It does not need any training and does not consult centralized white or black lists. Furthermore, it is simple to configure, requiring only 11 rules to determine the veracity of an incoming email. We compare the performance of phishwish to SpamAssassin and to Google's browser-based Phishing Filter. Our results indicate that phishwish outperforms these Filters and identifies zero days attacks that went undetected by existing Filters.

D. L. Cook - One of the best experts on this subject based on the ideXlab platform.

  • Phishwish: a simple and stateless Phishing Filter
    SECURITY AND COMMUNICATION NETWORKS, 2009
    Co-Authors: D. L. Cook, Vijay K Gurbani, M Daniluk
    Abstract:

    We define Phishing as the practice of directing unsuspecting users to fraudulent websites with the intent of obtaining personal information to be used for illicit purpose by a spammer. We introduce a new anti-Phishing Filter, phishwish, that has a number of advantages over existing Phishing Filters: it does not need to be trained, as is the case with Bayesian Filters, nor does it consult centralized white or blacklists to determine whether an email is suspect. Phishwish uses a set of only 11 rules to determine the veracity of an incoming email; the results can be used to quarantine the email or to alert the user. We compare the performance of phishwish to {SpamAssassin}, a popular open source Filter, as well as the Google Phishing Filters accessed from the Firefox browser. Our results indicate that phishwish outperforms existing Filters in identifying Phishing emails, even identifying those originated by the 'rock phish' gang, and that it aids in detection of zero-day attacks that were not caught by existing Filters. Copyright (C) 2008 John Wiley & Sons, Ltd.

  • Phishwish: A stateless Phishing Filter using minimal rules
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2008
    Co-Authors: D. L. Cook, Vijay K Gurbani, M Daniluk
    Abstract:

    We introduce phishwish, a Phishing Filter that offers advan- tages over existing Filters: It does not need any training and does not consult centralized white or black lists. Furthermore, it is simple to con- figure, requiring only 11 rules to determine the veracity of an incoming email.We compare the performance of phishwish to SpamAssassin and to Google’s browser-based Phishing Filter. Our results indicate that phish- wish outperforms these Filters and identifies zero days attacks that went undetected by existing Filters.

  • Financial Cryptography - Phishwish: A Stateless Phishing Filter Using Minimal Rules
    Financial Cryptography and Data Security, 1
    Co-Authors: D. L. Cook, Vijay K Gurbani, M Daniluk
    Abstract:

    We introduce phishwish, a Phishing Filter that offers advantages over existing Filters: It does not need any training and does not consult centralized white or black lists. Furthermore, it is simple to configure, requiring only 11 rules to determine the veracity of an incoming email. We compare the performance of phishwish to SpamAssassin and to Google's browser-based Phishing Filter. Our results indicate that phishwish outperforms these Filters and identifies zero days attacks that went undetected by existing Filters.

Vijay K Gurbani - One of the best experts on this subject based on the ideXlab platform.

  • Phishwish: a simple and stateless Phishing Filter
    SECURITY AND COMMUNICATION NETWORKS, 2009
    Co-Authors: D. L. Cook, Vijay K Gurbani, M Daniluk
    Abstract:

    We define Phishing as the practice of directing unsuspecting users to fraudulent websites with the intent of obtaining personal information to be used for illicit purpose by a spammer. We introduce a new anti-Phishing Filter, phishwish, that has a number of advantages over existing Phishing Filters: it does not need to be trained, as is the case with Bayesian Filters, nor does it consult centralized white or blacklists to determine whether an email is suspect. Phishwish uses a set of only 11 rules to determine the veracity of an incoming email; the results can be used to quarantine the email or to alert the user. We compare the performance of phishwish to {SpamAssassin}, a popular open source Filter, as well as the Google Phishing Filters accessed from the Firefox browser. Our results indicate that phishwish outperforms existing Filters in identifying Phishing emails, even identifying those originated by the 'rock phish' gang, and that it aids in detection of zero-day attacks that were not caught by existing Filters. Copyright (C) 2008 John Wiley & Sons, Ltd.

  • Phishwish: A stateless Phishing Filter using minimal rules
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2008
    Co-Authors: D. L. Cook, Vijay K Gurbani, M Daniluk
    Abstract:

    We introduce phishwish, a Phishing Filter that offers advan- tages over existing Filters: It does not need any training and does not consult centralized white or black lists. Furthermore, it is simple to con- figure, requiring only 11 rules to determine the veracity of an incoming email.We compare the performance of phishwish to SpamAssassin and to Google’s browser-based Phishing Filter. Our results indicate that phish- wish outperforms these Filters and identifies zero days attacks that went undetected by existing Filters.

  • Financial Cryptography - Phishwish: A Stateless Phishing Filter Using Minimal Rules
    Financial Cryptography and Data Security, 1
    Co-Authors: D. L. Cook, Vijay K Gurbani, M Daniluk
    Abstract:

    We introduce phishwish, a Phishing Filter that offers advantages over existing Filters: It does not need any training and does not consult centralized white or black lists. Furthermore, it is simple to configure, requiring only 11 rules to determine the veracity of an incoming email. We compare the performance of phishwish to SpamAssassin and to Google's browser-based Phishing Filter. Our results indicate that phishwish outperforms these Filters and identifies zero days attacks that went undetected by existing Filters.

Dijiang Huang - One of the best experts on this subject based on the ideXlab platform.

  • SOSE - Secure Web Referral Services for Mobile Cloud Computing
    2013 IEEE Seventh International Symposium on Service-Oriented System Engineering, 2013
    Co-Authors: Vijayakrishnan Nagarajan, Dijiang Huang, Wei-tek Tsai
    Abstract:

    Security has become a major concern for mobile devices when mobile users browsing malicious websites. Existed security solutions may rely on human factors to achieve a good result against Phishing websites and SSL Strip-based Man-In-The-Middle (MITM) attack. This paper presents a secure web referral service, which is called Secure Search Engine (SSE) for mobile devices. The system uses mobile cloud-based virtual computing and provides each user a Virtual Machine (VM) as a personal security proxy where all Web traffics are redirected through it. Within the VM, the SSE uses web crawling technology with a set of checking services to validate IP addresses and certificate chains. A Phishing Filter is also used to check given URLs with an optimized execution time. The system also uses private and anonymously shared caches to protect user privacy and improve performance. The evaluation results show that SSE is non-intrusive and consumes no power or computation on the client device, while producing less false positive and false negative than existing web browser-based anti-Phishing solutions.

  • ICOIN - Secure web referral service
    The International Conference on Information Network 2012, 2012
    Co-Authors: Vijayakrishnan Nagarajan, Dijiang Huang
    Abstract:

    Security has become a major concern while browsing as the number of malicious sites keeps increasing with the cost for hosting a site decreasing. Though most of the web servers use Secure Socket Layer (SSL) over HTTP (Hyper Text Transfer Protocol) to ensure trust between consumers and providers, SSL is vulnerable to Man-In-The-Middle (MITM) attack and becoming very common these days. Phishing is another major problem, which has increased rapidly over the years. In this paper we present a novel secure web referral service using Secure Search Engine (SSE), which would resolve Phishing and MITM attacks for web based applications. SSE is based on web crawling technology with a set of checking services to validate IP addresses and certificate chains. Additionally, we present a novel Phishing Filter that can be used to check any given URLs with minimal delay. Our solution is non-intrusive and reduces human factors, which are commonly in existing web-based services, in security verification processes. Our evaluation shows that our solutions produce less false positive and false negative than existing web browser-based anti-Phishing solutions.

Vijayakrishnan Nagarajan - One of the best experts on this subject based on the ideXlab platform.

  • SOSE - Secure Web Referral Services for Mobile Cloud Computing
    2013 IEEE Seventh International Symposium on Service-Oriented System Engineering, 2013
    Co-Authors: Vijayakrishnan Nagarajan, Dijiang Huang, Wei-tek Tsai
    Abstract:

    Security has become a major concern for mobile devices when mobile users browsing malicious websites. Existed security solutions may rely on human factors to achieve a good result against Phishing websites and SSL Strip-based Man-In-The-Middle (MITM) attack. This paper presents a secure web referral service, which is called Secure Search Engine (SSE) for mobile devices. The system uses mobile cloud-based virtual computing and provides each user a Virtual Machine (VM) as a personal security proxy where all Web traffics are redirected through it. Within the VM, the SSE uses web crawling technology with a set of checking services to validate IP addresses and certificate chains. A Phishing Filter is also used to check given URLs with an optimized execution time. The system also uses private and anonymously shared caches to protect user privacy and improve performance. The evaluation results show that SSE is non-intrusive and consumes no power or computation on the client device, while producing less false positive and false negative than existing web browser-based anti-Phishing solutions.

  • ICOIN - Secure web referral service
    The International Conference on Information Network 2012, 2012
    Co-Authors: Vijayakrishnan Nagarajan, Dijiang Huang
    Abstract:

    Security has become a major concern while browsing as the number of malicious sites keeps increasing with the cost for hosting a site decreasing. Though most of the web servers use Secure Socket Layer (SSL) over HTTP (Hyper Text Transfer Protocol) to ensure trust between consumers and providers, SSL is vulnerable to Man-In-The-Middle (MITM) attack and becoming very common these days. Phishing is another major problem, which has increased rapidly over the years. In this paper we present a novel secure web referral service using Secure Search Engine (SSE), which would resolve Phishing and MITM attacks for web based applications. SSE is based on web crawling technology with a set of checking services to validate IP addresses and certificate chains. Additionally, we present a novel Phishing Filter that can be used to check any given URLs with minimal delay. Our solution is non-intrusive and reduces human factors, which are commonly in existing web-based services, in security verification processes. Our evaluation shows that our solutions produce less false positive and false negative than existing web browser-based anti-Phishing solutions.