The Experts below are selected from a list of 1650 Experts worldwide ranked by ideXlab platform

Mario Fritz - One of the best experts on this subject based on the ideXlab platform.

  • CCS - VisualPhishNet: Zero-Day Phishing Website Detection by Visual Similarity.
    Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, 2020
    Co-Authors: Sahar Abdelnabi, Katharina Krombholz, Mario Fritz
    Abstract:

    Phishing Websites are still a major threat in today's Internet ecosystem. Despite numerous previous efforts, similarity-based detection methods do not offer sufficient protection for the trusted Websites -- in particular against unseen Phishing pages. This paper contributes VisualPhishNet, a new similarity-based Phishing detection framework, based on a triplet Convolutional Neural Network (CNN). VisualPhishNet learns profiles for Websites in order to detect Phishing Websites by a similarity metric that can generalize to pages with new visual appearances. We furthermore present VisualPhish, the largest dataset to date that facilitates visual Phishing detection in an ecologically valid manner. We show that our method outperforms previous visual similarity Phishing detection approaches by a large margin while being robust against a range of evasion attacks.

  • WhiteNet: Phishing Website Detection by Visual Whitelists
    arXiv: Cryptography and Security, 2019
    Co-Authors: Sahar Abdelnabi, Katharina Krombholz, Mario Fritz
    Abstract:

    Phishing Websites are still a major threat in today's Internet ecosystem. Despite numerous previous efforts, black and white listing methods do not offer sufficient protection - in particular against zero-day Phishing attacks. This paper contributes WhiteNet, a new similarity-based Phishing detection framework, based on a triplet network with three shared Convolutional Neural Networks (CNNs). WhiteNet learns profiles for Websites in order to detect zero-day Phishing Websites by a "visual whitelist". We furthermore present WhitePhish, the largest dataset to date that facilitates visual Phishing detection in an ecologically valid manner. We show that our method outperforms the state-of-the-art by a large margin while being robust against a range of evasion attacks.

  • whitenet Phishing Website detection by visual whitelists
    2019
    Co-Authors: Sahar Abdelnabi, Katharina Krombholz, Mario Fritz
    Abstract:

    Phishing Websites are still a major threat in today's Internet ecosystem. Despite numerous previous efforts, similarity-based detection methods do not offer sufficient protection for the trusted Websites - in particular against unseen Phishing pages. This paper contributes VisualPhishNet, a new similarity-based Phishing detection framework, based on a triplet Convolutional Neural Network (CNN). VisualPhishNet learns profiles for Websites in order to detect Phishing Websites by a similarity metric that can generalize to pages with new visual appearances. We furthermore present VisualPhish, the largest dataset to date that facilitates visual Phishing detection in an ecologically valid manner. We show that our method outperforms previous visual similarity Phishing detection approaches by a large margin while being robust against a range of evasion attacks.

  • VisualPhishNet: Zero-Day Phishing Website Detection by Visual Similarity
    arXiv: Cryptography and Security, 2019
    Co-Authors: Sahar Abdelnabi, Katharina Krombholz, Mario Fritz
    Abstract:

    Phishing Websites are still a major threat in today's Internet ecosystem. Despite numerous previous efforts, similarity-based detection methods do not offer sufficient protection for the trusted Websites - in particular against unseen Phishing pages. This paper contributes VisualPhishNet, a new similarity-based Phishing detection framework, based on a triplet Convolutional Neural Network (CNN). VisualPhishNet learns profiles for Websites in order to detect Phishing Websites by a similarity metric that can generalize to pages with new visual appearances. We furthermore present VisualPhish, the largest dataset to date that facilitates visual Phishing detection in an ecologically valid manner. We show that our method outperforms previous visual similarity Phishing detection approaches by a large margin while being robust against a range of evasion attacks.

  • WhiteNet: Zero-Day Phishing Website Detection by Visual Whitelists
    arXiv: Cryptography and Security, 2019
    Co-Authors: Sahar Abdelnabi, Katharina Krombholz, Mario Fritz
    Abstract:

    Phishing Websites are still a major threat in today's Internet ecosystem. Despite numerous previous efforts, black and whitelisting methods do not offer sufficient protection, in particular against zero-day Phishing attacks. This paper contributes WhiteNet, a new similarity-based Phishing detection framework, based on a triplet network with three shared Convolutional Neural Networks (CNNs). WhiteNet learns profiles for Websites in order to detect zero-day Phishing Websites by a "visual whitelist". We furthermore present WhitePhish, the largest dataset to date that facilitates visual Phishing detection in an ecologically valid manner. We show that our method detects zero-day pages and outperforms previous visual similarity Phishing detection approaches by a large margin while being robust against a range of evasion attacks.

Keshav Dahal - One of the best experts on this subject based on the ideXlab platform.

  • Phishing Website Detection using Intelligent Data Mining Techniques: Design and Development of an Intelligent Association Classification Fuzzy Based Scheme for Phishing Website Detection
    2012
    Co-Authors: Maher Aburrous, Alamgir Hossain, Keshav Dahal
    Abstract:

    Detecting Phishing Website is a complex task which requires significant expert knowledge and experience. So far, various solutions have been proposed and developed to address these problems. Most of these approaches are not able to make a decision dynamically, giving rise to a large number of false positives. This is mainly due to limitation of the previously proposed approaches. In this book, we investigate and develop the application of an intelligent fuzzy-based classification system for Phishing Website detection. The proposed intelligent Phishing detection system employed Fuzzy Logic (FL) model with association classification mining algorithms. Different Phishing experiments which cover all Phishing attacks, motivations and deception behavior techniques have been conducted to cover all Phishing concerns. A comparative study and analysis showed that the proposed learning approach has a higher degree of predictive and detective capability than existing models. The proposed system was developed, tested and validated by incorporating the scheme as a web based plug-ins Phishing toolbar to provide an effective help for real-time Phishing Website detection for all internet users.

  • Phishing Website Detection using Intelligent Data Mining Techniques
    2012
    Co-Authors: Maher Aburrous, Alamgir Hossain, Keshav Dahal
    Abstract:

    Detecting Phishing Website is a complex task which requires significant expert knowledge and experience. So far, various solutions have been proposed and developed to address these problems. Most of these approaches are not able to make a decision dynamically, giving rise to a large number of false positives. This is mainly due to limitation of the previously proposed approaches. In this book, we investigate and develop the application of an intelligent fuzzy-based classification system for Phishing Website detection. The proposed intelligent Phishing detection system employed Fuzzy Logic (FL) model with association classification mining algorithms. Different Phishing experiments which cover all Phishing attacks, motivations and deception behavior techniques have been conducted to cover all Phishing concerns. A comparative study and analysis showed that the proposed learning approach has a higher degree of predictive and detective capability than existing models. The proposed system was developed, tested and validated by incorporating the scheme as a web based plug-ins Phishing toolbar to provide an effective help for real-time Phishing Website detection for all internet users.

  • intelligent Phishing detection system for e banking using fuzzy data mining
    Expert Systems With Applications, 2010
    Co-Authors: Maher Aburrous, Keshav Dahal, M A Hossain, Fadi Thabtah
    Abstract:

    Detecting and identifying any Phishing Websites in real-time, particularly for e-banking, is really a complex and dynamic problem involving many factors and criteria. Because of the subjective considerations and the ambiguities involved in the detection, fuzzy data mining techniques can be an effective tool in assessing and identifying Phishing Websites for e-banking since it offers a more natural way of dealing with quality factors rather than exact values. In this paper, we present novel approach to overcome the 'fuzziness' in the e-banking Phishing Website assessment and propose an intelligent resilient and effective model for detecting e-banking Phishing Websites. The proposed model is based on fuzzy logic combined with data mining algorithms to characterize the e-banking Phishing Website factors and to investigate its techniques by classifying the Phishing types and defining six e-banking Phishing Website attack criteria's with a layer structure. Our experimental results showed the significance and importance of the e-banking Phishing Website criteria (URL & Domain Identity) represented by layer one and the various influence of the Phishing characteristic on the final e-banking Phishing Website rate.

  • Associative Classification techniques for predicting e-banking Phishing Websites
    2010 International Conference on Multimedia Computing and Information Technology (MCIT), 2010
    Co-Authors: Maher Aburrous, Keshav Dahal, Mohammed Alamgir Hossain, Fadi Thabtah
    Abstract:

    This paper presents a novel approach to overcome the difficulty and complexity in detecting and predicting e-banking Phishing Website. We proposed an intelligent resilient and effective model that is based on using association and classification Data Mining algorithms. These algorithms were used to characterize and identify all the factors and rules in order to classify the Phishing Website and the relationship that correlate them with each other. We implemented six different classification algorithm and techniques to extract the Phishing training data sets criteria to classify their legitimacy. We also compared their performances, accuracy, number of rules generated and speed. The rules generated from the associative classification model showed the relationship between some important characteristics like URL and Domain Identity, and Security and Encryption criteria in the final Phishing detection rate. The experimental results demonstrated the feasibility of using Associative Classification techniques in real applications and its better performance as compared to other traditional classifications algorithms.

  • ITNG - Predicting Phishing Websites Using Classification Mining Techniques with Experimental Case Studies
    2010 Seventh International Conference on Information Technology: New Generations, 2010
    Co-Authors: Maher Aburrous, Keshav Dahal, Mohammed Alamgir Hossain, Fadi Thabtah
    Abstract:

    Classification Data Mining (DM) Techniques can be a very useful tool in detecting and identifying e-banking Phishing Websites. In this paper, we present a novel approach to overcome the difficulty and complexity in detecting and predicting e-banking Phishing Website. We proposed an intelligent resilient and effective model that is based on using association and classification Data Mining algorithms. These algorithms were used to characterize and identify all the factors and rules in order to classify the Phishing Website and the relationship that correlate them with each other. We implemented six different classification algorithm and techniques to extract the Phishing training data sets criteria to classify their legitimacy. We also compared their performances, accuracy, number of rules generated and speed. A Phishing Case study was applied to illustrate the Website Phishing process. The rules generated from the associative classification model showed the relationship between some important characteristics like URL and Domain Identity, and Security and Encryption criteria in the final Phishing detection rate. The experimental results demonstrated the feasibility of using Associative Classification techniques in real applications and its better performance as compared to other traditional classifications algorithms.

Maher Aburrous - One of the best experts on this subject based on the ideXlab platform.

  • Phishing Website Detection using Intelligent Data Mining Techniques: Design and Development of an Intelligent Association Classification Fuzzy Based Scheme for Phishing Website Detection
    2012
    Co-Authors: Maher Aburrous, Alamgir Hossain, Keshav Dahal
    Abstract:

    Detecting Phishing Website is a complex task which requires significant expert knowledge and experience. So far, various solutions have been proposed and developed to address these problems. Most of these approaches are not able to make a decision dynamically, giving rise to a large number of false positives. This is mainly due to limitation of the previously proposed approaches. In this book, we investigate and develop the application of an intelligent fuzzy-based classification system for Phishing Website detection. The proposed intelligent Phishing detection system employed Fuzzy Logic (FL) model with association classification mining algorithms. Different Phishing experiments which cover all Phishing attacks, motivations and deception behavior techniques have been conducted to cover all Phishing concerns. A comparative study and analysis showed that the proposed learning approach has a higher degree of predictive and detective capability than existing models. The proposed system was developed, tested and validated by incorporating the scheme as a web based plug-ins Phishing toolbar to provide an effective help for real-time Phishing Website detection for all internet users.

  • Phishing Website Detection using Intelligent Data Mining Techniques
    2012
    Co-Authors: Maher Aburrous, Alamgir Hossain, Keshav Dahal
    Abstract:

    Detecting Phishing Website is a complex task which requires significant expert knowledge and experience. So far, various solutions have been proposed and developed to address these problems. Most of these approaches are not able to make a decision dynamically, giving rise to a large number of false positives. This is mainly due to limitation of the previously proposed approaches. In this book, we investigate and develop the application of an intelligent fuzzy-based classification system for Phishing Website detection. The proposed intelligent Phishing detection system employed Fuzzy Logic (FL) model with association classification mining algorithms. Different Phishing experiments which cover all Phishing attacks, motivations and deception behavior techniques have been conducted to cover all Phishing concerns. A comparative study and analysis showed that the proposed learning approach has a higher degree of predictive and detective capability than existing models. The proposed system was developed, tested and validated by incorporating the scheme as a web based plug-ins Phishing toolbar to provide an effective help for real-time Phishing Website detection for all internet users.

  • intelligent Phishing detection system for e banking using fuzzy data mining
    Expert Systems With Applications, 2010
    Co-Authors: Maher Aburrous, Keshav Dahal, M A Hossain, Fadi Thabtah
    Abstract:

    Detecting and identifying any Phishing Websites in real-time, particularly for e-banking, is really a complex and dynamic problem involving many factors and criteria. Because of the subjective considerations and the ambiguities involved in the detection, fuzzy data mining techniques can be an effective tool in assessing and identifying Phishing Websites for e-banking since it offers a more natural way of dealing with quality factors rather than exact values. In this paper, we present novel approach to overcome the 'fuzziness' in the e-banking Phishing Website assessment and propose an intelligent resilient and effective model for detecting e-banking Phishing Websites. The proposed model is based on fuzzy logic combined with data mining algorithms to characterize the e-banking Phishing Website factors and to investigate its techniques by classifying the Phishing types and defining six e-banking Phishing Website attack criteria's with a layer structure. Our experimental results showed the significance and importance of the e-banking Phishing Website criteria (URL & Domain Identity) represented by layer one and the various influence of the Phishing characteristic on the final e-banking Phishing Website rate.

  • Associative Classification techniques for predicting e-banking Phishing Websites
    2010 International Conference on Multimedia Computing and Information Technology (MCIT), 2010
    Co-Authors: Maher Aburrous, Keshav Dahal, Mohammed Alamgir Hossain, Fadi Thabtah
    Abstract:

    This paper presents a novel approach to overcome the difficulty and complexity in detecting and predicting e-banking Phishing Website. We proposed an intelligent resilient and effective model that is based on using association and classification Data Mining algorithms. These algorithms were used to characterize and identify all the factors and rules in order to classify the Phishing Website and the relationship that correlate them with each other. We implemented six different classification algorithm and techniques to extract the Phishing training data sets criteria to classify their legitimacy. We also compared their performances, accuracy, number of rules generated and speed. The rules generated from the associative classification model showed the relationship between some important characteristics like URL and Domain Identity, and Security and Encryption criteria in the final Phishing detection rate. The experimental results demonstrated the feasibility of using Associative Classification techniques in real applications and its better performance as compared to other traditional classifications algorithms.

  • ITNG - Predicting Phishing Websites Using Classification Mining Techniques with Experimental Case Studies
    2010 Seventh International Conference on Information Technology: New Generations, 2010
    Co-Authors: Maher Aburrous, Keshav Dahal, Mohammed Alamgir Hossain, Fadi Thabtah
    Abstract:

    Classification Data Mining (DM) Techniques can be a very useful tool in detecting and identifying e-banking Phishing Websites. In this paper, we present a novel approach to overcome the difficulty and complexity in detecting and predicting e-banking Phishing Website. We proposed an intelligent resilient and effective model that is based on using association and classification Data Mining algorithms. These algorithms were used to characterize and identify all the factors and rules in order to classify the Phishing Website and the relationship that correlate them with each other. We implemented six different classification algorithm and techniques to extract the Phishing training data sets criteria to classify their legitimacy. We also compared their performances, accuracy, number of rules generated and speed. A Phishing Case study was applied to illustrate the Website Phishing process. The rules generated from the associative classification model showed the relationship between some important characteristics like URL and Domain Identity, and Security and Encryption criteria in the final Phishing detection rate. The experimental results demonstrated the feasibility of using Associative Classification techniques in real applications and its better performance as compared to other traditional classifications algorithms.

Bruhadeshwar Bezawada - One of the best experts on this subject based on the ideXlab platform.

  • kn0w thy doma1n name unbiased Phishing detection using domain name based features
    Symposium on Access Control Models and Technologies, 2018
    Co-Authors: Hossein Shirazi, Bruhadeshwar Bezawada
    Abstract:

    Phishing Websites remain a persistent security threat. Thus far, machine learning approaches appear to have the best potential as defenses. But, there are two main concerns with existing machine learning approaches for Phishing detection. The first is the large number of training features used and the lack of validating arguments for these feature choices. The second concern is the type of datasets used in the literature that are inadvertently biased with respect to the features based on the Website URL or content. To address these concerns, we put forward the intuition that the domain name of Phishing Websites is the tell-tale sign of Phishing and holds the key to successful Phishing detection. Accordingly, we design features that model the relationships, visual as well as statistical, of the domain name to the key elements of a Phishing Website, which are used to snare the end-users. The main value of our feature design is that, to bypass detection, an attacker will find it very difficult to tamper with the visual content of the Phishing Website without arousing the suspicion of the end user. Our feature set ensures that there is minimal or no bias with respect to a dataset. Our learning model trains with only seven features and achieves a true positive rate of 98% and a classification accuracy of 97%, on sample dataset. Compared to the state-of-the-art work, our per data instance classification is 4 times faster for legitimate Websites and 10 times faster for Phishing Websites. Importantly, we demonstrate the shortcomings of using features based on URLs as they are likely to be biased towards specific datasets. We show the robustness of our learning algorithm by testing on unknown live Phishing URLs and achieve a high detection accuracy of $99.7%$.

  • SACMAT - "Kn0w Thy Doma1n Name" : Unbiased Phishing Detection Using Domain Name Based Features
    Proceedings of the 23nd ACM on Symposium on Access Control Models and Technologies, 2018
    Co-Authors: Hossein Shirazi, Bruhadeshwar Bezawada
    Abstract:

    Phishing Websites remain a persistent security threat. Thus far, machine learning approaches appear to have the best potential as defenses. But, there are two main concerns with existing machine learning approaches for Phishing detection. The first is the large number of training features used and the lack of validating arguments for these feature choices. The second concern is the type of datasets used in the literature that are inadvertently biased with respect to the features based on the Website URL or content. To address these concerns, we put forward the intuition that the domain name of Phishing Websites is the tell-tale sign of Phishing and holds the key to successful Phishing detection. Accordingly, we design features that model the relationships, visual as well as statistical, of the domain name to the key elements of a Phishing Website, which are used to snare the end-users. The main value of our feature design is that, to bypass detection, an attacker will find it very difficult to tamper with the visual content of the Phishing Website without arousing the suspicion of the end user. Our feature set ensures that there is minimal or no bias with respect to a dataset. Our learning model trains with only seven features and achieves a true positive rate of 98% and a classification accuracy of 97%, on sample dataset. Compared to the state-of-the-art work, our per data instance classification is 4 times faster for legitimate Websites and 10 times faster for Phishing Websites. Importantly, we demonstrate the shortcomings of using features based on URLs as they are likely to be biased towards specific datasets. We show the robustness of our learning algorithm by testing on unknown live Phishing URLs and achieve a high detection accuracy of $99.7%$.

Weiwei Zhuang - One of the best experts on this subject based on the ideXlab platform.

  • ICDCS Workshops - An Intelligent Anti-Phishing Strategy Model for Phishing Website Detection
    2012 32nd International Conference on Distributed Computing Systems Workshops, 2012
    Co-Authors: Weiwei Zhuang, Qingshan Jiang, Tengke Xiong
    Abstract:

    As a new form of malicious software, Phishing Websites appear frequently in recent years, which cause great harm to online financial services and data security. In this paper, we design and implement an intelligent model for detecting Phishing Websites. In this model, we extract 10 different types of features such as title, keyword and link text information to represent the Website. Heterogeneous classifiers are then built based on these different features. We propose a principled ensemble classification algorithm to combine the predicted results from different Phishing detection classifiers. Hierarchical clustering technique has been employed for automatic Phishing categorization. Case studies on large and real daily Phishing Websites collected from King soft Internet Security Lab demonstrate that our proposed model outperforms other commonly used anti-Phishing methods and tools in Phishing Website detection.

  • Ensemble clustering for internet security applications
    IEEE Transactions on Systems, Man and Cybernetics Part C: Applications and Reviews, 2012
    Co-Authors: Weiwei Zhuang, Y.a Ye, Yong Chen, Tao Li
    Abstract:

    Due to their damage to Internet security, malware and Phishing Website detection has been the Internet security topics that are of great interests. Compared with malware attacks, Phishing Website fraud is a relatively new Internet crime. However, they share some common properties: 1) both malware samples and Phishing Websites are created at a rate of thousands per day driven by economic benefits; and 2) Phishing Websites represented by the term frequencies of the webpage content share similar characteristics with malware samples represented by the instruction frequencies of the program. Over the past few years, many clustering techniques have been employed for automatic malware and Phishing Website detection. In these techniques, the detection process is generally divided into two steps: 1) feature extraction, where representative features are extracted to capture the characteristics of the file samples or the Websites; and 2) categorization, where intelligent techniques are used to automatically group the file samples or Websites into different classes based on computational analysis of the feature representations. However, few have been applied in real industry products. In this paper, we develop an automatic categorization system to automatically group Phishing Websites or malware samples using a cluster ensemble by aggregating the clustering solutions that are generated by different base clustering algorithms. We propose a principled cluster ensemble framework to combine individual clustering solutions that are based on the consensus partition, which can not only be applied for malware categorization, but also for Phishing Website clustering. In addition, the domain knowledge in the form of sample-level/Website-level constraints can be naturally incorporated into the ensemble framework. The case studies on large and real daily Phishing Websites and malware collection from the Kingsoft Internet Security Laboratory demonstrate the effectiveness and efficiency of - ur proposed method.

  • An intelligent anti-Phishing strategy model for Phishing Website detection
    Proceedings - 32nd IEEE International Conference on Distributed Computing Systems Workshops, ICDCSW 2012, 2012
    Co-Authors: Weiwei Zhuang, Qingshan Jiang, Tengke Xiong
    Abstract:

    As a new form of malicious software, Phishing Websites appear frequently in recent years, which cause great harm to online financial services and data security. In this paper, we design and implement an intelligent model for detecting Phishing Websites. In this model, we extract 10 different types of features such as title, keyword and link text information to represent the Website. Heterogeneous classifiers are then built based on these different features. We propose a principled ensemble classification algorithm to combine the predicted results from different Phishing detection classifiers. Hierarchical clustering technique has been employed for automatic Phishing categorization. Case studies on large and real daily Phishing Websites collected from King soft Internet Security Lab demonstrate that our proposed model outperforms other commonly used anti-Phishing methods and tools in Phishing Website detection.