Netting Phish in the IPFS Ocean: Real-Time Monitoring and Characterization of Decentralized Phishing Campaigns
Anas Kastantin, Leonhard Balduf, Onur Ascigil, Saidu Sokoto, Björn Scheuermann, Andrzej Duda, Michal Król, Maciej Korczynski
Abstract
The InterPlanetary File System (IPFS) is the largest decentralized content-centric storage network. While its architecture enables resilient, distributed content delivery, it can be abused to host and disseminate malicious content. Public IPFS HTTP gateways further expand this threat surface, enabling attackers to deploy phishing websites and leverage gateway reputation to evade detection. This model can keep content available even after attackers go offline and challenges traditional phishing detection systems. We present a framework for monitoring and characterizing phishing on IPFS, leveraging a measurement platform that integrates multi-source data, including IPFS traffic and passive DNS. Over 11 months, we detect 10,489 phishing CIDs, grouped into 448 phishing clusters. 80% of detected CIDs originate from only 69 clustered campaigns indicating that targeting a small number of dominant clusters could yield high mitigation leverage. We also identify 588 gateways involved in dissemination, including 573 outside public gateway lists, and show that attackers can exploit caching across reputable gateways to amplify attacks and extend content availability. Finally, we find that traditional Web phishing countermeasures and IPFS blocklists provide insufficient protection. Our findings support practical mitigation and offer broader insights for trust and safety in decentralized web infrastructures. CCS Concepts • Security and privacy → Phishing; Web protocol security; Distributed systems security; • Networks → Network measurement; Peer-to-peer protocols; Peer-to-peer networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cee29d68-b38e-4907-b8dd-94a1cb5b77b9Builds on10
- Design and evaluation of IPFS: a storage layer for the decentralized webDennis Trautwein, Aravindh Raman, Gareth Tyson, Ignacio Castro et al.SIGCOMM 2022 · 188 citations
- Understanding Security Issues in the NFT EcosystemDipanjan Das, Priyanka Bose, Nicola Ruaro, Christopher Kruegel et al.CCS 2022 · 173 citations
- Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing WebpagesYun Lin, Ruofan Liu, Dinil Mon Divakaran, Jun Yang Ng et al.USENIX Security 2021 · 164 citations
- Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared HostingSamaneh Tajalizadehkhoob, Tom van Goethem, Maciej Korczynski, Arman Noroozian et al.CCS 2017 · 48 citations
- Compromised or Attacker-Owned: A Large Scale Classification and Study of Hosting Domains of Malicious URLsRavindu De Silva, Mohamed Nabeel, Charith Elvitigala, Issa Khalil et al.USENIX Security 2021 · 45 citations
Related papers
- Guardians of the Galaxy: Content Moderation in the InterPlanetary File SystemSaidu Sokoto, Leonhard Balduf, Dennis Trautwein, Yiluo Wei et al.USENIX Security 2024 · 6 citations
- Content Censorship in the InterPlanetary File SystemSrivatsan Sridhar, Onur Ascigil, Navin V. Keizer, François Genon et al.NDSS 2024
- Total Eclipse of the Heart - Disrupting the InterPlanetary File SystemBernd Prünster, Alexander Marsalek, Thomas ZeffererUSENIX Security 2022
- The Eternal Tussle: Exploring the Role of Centralization in IPFSYiluo Wei, Dennis Trautwein, Yiannis Psaras, Ignacio Castro et al.NSDI 2024 · 14 citations
- Sunrise to Sunset: Analyzing the End-to-end Life Cycle and Effectiveness of Phishing Attacks at ScaleAdam Oest, Penghui Zhang, Brad Wardman, Eric Nunes et al.USENIX Security 2020
