PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing Blacklists
Adam Oest, Yeganeh Safaei, Penghui Zhang, Brad Wardman, Kevin Tyers, Yan Shoshitaishvili, Adam Doupé
摘要
Due to their ubiquity in modern web browsers, antiphishing blacklists are a key defense against large-scale phishing attacks. However, sophistication in phishing websites-such as evasion techniques that seek to defeat these blacklists-continues to grow. Yet, the e ectiveness of blacklists against evasive websites is di cult to measure, and there have been no methodical e orts to make and track such measurements, at the ecosystem level, over time. We propose a framework for continuously identifying unmitigated phishing websites in the wild, replicating key aspects of theircon guration in a controlled setting,and generating longitudinal experiments to measure the ecosystem's protection. In six experiment deployments over nine months, we systematically launch and report 2,862 new (innocuous) phishing websites to evaluate the performance (speed and coverage) and consistency of blacklists, with the goal of improving them. We show that methodical long-term empirical measurements are an e ective strategy for proactively detecting weaknesses in the anti-phishing ecosystem. Through our experiments, we identify and disclose several such weaknesses, including a class of behavior-based JavaScript evasion that blacklists were unable to detect. We nd that enhanced protections on mobile devices and the expansion of evidence-based reporting protocols are critical ecosystem improvements that could better protect users against modern phishing attacks, which routinely seek to evade detection infrastructure.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper30
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson 等USENIX Security 2021 · 被引用 42 次
- TxPhishScope: Towards Detecting and Understanding Transaction-based Phishing on EthereumBowen He, Yuan Chen, Zhuo Chen, Xiaohui Hu 等CCS 2023 · 被引用 38 次
- PhishPrint: Evading Phishing Detection Crawlers by Prior ProfilingBhupendra Acharya, Phani VadrevuUSENIX Security 2021 · 被引用 37 次
- Analyzing Ground-Truth Data of Mobile Gambling ScamsGeng Hong, Zhemin Yang, Sen Yang, Xiaojing Liao 等S&P 2022 · 被引用 29 次
- Assessing Browser-level Defense against IDN-based PhishingHang Hu, Steve T. K. Jan, Yang Wang, Gang WangUSENIX Security 2021 · 被引用 22 次
它引用的顶会 Paper6
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett 等CCS 2017 · 被引用 248 次
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy 等USENIX Security 2019 · 被引用 123 次
- PhishEye: Live Monitoring of Sandboxed Phishing KitsXiao Han, Nizar Kheir, Davide BalzarottiCCS 2016 · 被引用 118 次
- Detecting and Characterizing Lateral Phishing at ScaleGrant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser 等USENIX Security 2019 · 被引用 113 次
- Cognitive Triaging of Phishing AttacksAmber van der Heijden, Luca AllodiUSENIX Security 2019 · 被引用 100 次
相关 Paper
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn 等S&P 2019 · 被引用 129 次
- CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in PhishingPenghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun 等S&P 2021 · 被引用 1 次
- PhishinWebView: Analysis of Anti-Phishing Entities in Mobile Apps with WebView Targeted PhishingYoonjung Choi, Woonghee Lee, Junbeom HurWWW 2024 · 被引用 5 次
- A Good Fishman Knows All the Angles: A Critical Evaluation of Google's Phishing Page ClassifierChangqing Miao, Jianan Feng, Wei You, Wenchang Shi 等CCS 2023 · 被引用 2 次
- SoK: PHILTER: Uncovering Security and Functional Gaps in AI-based Phishing Website Detection Literature via an LLM-based Reasoning FrameworkMahbub Alam, Muhammad Lutfor Rahman, Sonjoy Kumar Paul, Amy W. Hays 等USENIX Security 2026
