An Empirical Analysis of the Effectiveness of Browser-based Anti- phishing Solutions
نویسندگان
چکیده
Phishing has by far become the most dangerous form of fraud to hit online business. Due to the key role in accessing the Internet, web browsers are at a strategic position to offer the protection against the risks of phishing attacks. Varieties of security companies have proposed their browser-based antiphishing solutions to protect the end-use. In this paper, we used 3403 fresh phishing URLs and 1000 legitimate URLs to conduct four experiments on ten popular anti-phishing tools including browsers and browser plug-ins. Overall, we found that the Google Chrome and Firefox identified the most phishing sites, but these two browsers still missed more than 20% fraudulent sites. Qihoo 360 Secure Explorer did a strong performance under the APAC dataset that demonstrate their excellent abilities of the Chinese-target phishing detection. We also found that different anti-phishing tools have totally different reactions between regions and languages. And finally, we proposed our suggestions for designing a comprehensive anti-phishing mechanism.
منابع مشابه
Phinding Phish: Evaluating Anti-Phishing Tools
There are currently dozens of freely available tools to combat phishing and other web-based scams, many of which are web browser extensions that warn users when they are browsing a suspected phishing site. We developed an automated test bed for testing antiphishing tools. We used 200 verified phishing URLs from two sources and 516 legitimate URLs to test the effectiveness of 10 popular anti-phi...
متن کاملTabSecure: An Anti-Phishing Solution with Protection against Tabnabbing
With an upsurge in the use of internet, there are various attacks being launched every day. These attacks target the vulnerabilities of various computer resources, such as, the operating system, web browsers, toolbars, etc. along with the susceptibility of the users due to lack of awareness about the possible scams. The existing solutions suffer various drawbacks. The website phishing solutions...
متن کاملPhinding Phish: An Evaluation of Anti-Phishing Toolbars
There are currently dozens of freely available tools to combat phishing and other web-based scams, many of which are web browser extensions that warn users when they are browsing a suspected phishing site. We developed an automated test bed for testing antiphishing tools. We used 200 verified phishing URLs from two sources and 516 legitimate URLs to test the effectiveness of 10 popular anti-phi...
متن کاملToken Based Security for Prevention of Phishing Attack at Client Side
Phishing is an electronic identity theft in which the attacker uses a combination of social engineering techniques and web spoofing techniques to decept a user into revealing sensitive information. The literature addresses this issue extensively and presents a number of solutions, which are either client based or server based. Generally client based solutions have an upper hand over the server ...
متن کاملOn the Effectiveness of Techniques to Detect Phishing Sites
Abstract. Phishing is an electronic online identity theft in which the attackers use a combination of social engineering and web site spoofing techniques to trick a user into revealing confidential information. This information is typically used to make an illegal economic profit (e.g., by online banking transactions, purchase of goods using stolen credentials, etc.). Although simple, phishing ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2012