An Empirical Analysis of the Effectiveness of Browser-based Anti- phishing Solutions

نویسندگان

  • Jianyi Zhang
  • Chaohua Wu
  • Dan Li
  • Zhe Jia
  • Xi Ouyang
  • Yang Xin
چکیده

Phishing has by far become the most dangerous form of fraud to hit online business. Due to the key role in accessing the Internet, web browsers are at a strategic position to offer the protection against the risks of phishing attacks. Varieties of security companies have proposed their browser-based antiphishing solutions to protect the end-use. In this paper, we used 3403 fresh phishing URLs and 1000 legitimate URLs to conduct four experiments on ten popular anti-phishing tools including browsers and browser plug-ins. Overall, we found that the Google Chrome and Firefox identified the most phishing sites, but these two browsers still missed more than 20% fraudulent sites. Qihoo 360 Secure Explorer did a strong performance under the APAC dataset that demonstrate their excellent abilities of the Chinese-target phishing detection. We also found that different anti-phishing tools have totally different reactions between regions and languages. And finally, we proposed our suggestions for designing a comprehensive anti-phishing mechanism.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Phinding Phish: Evaluating Anti-Phishing Tools

There are currently dozens of freely available tools to combat phishing and other web-based scams, many of which are web browser extensions that warn users when they are browsing a suspected phishing site. We developed an automated test bed for testing antiphishing tools. We used 200 verified phishing URLs from two sources and 516 legitimate URLs to test the effectiveness of 10 popular anti-phi...

متن کامل

TabSecure: An Anti-Phishing Solution with Protection against Tabnabbing

With an upsurge in the use of internet, there are various attacks being launched every day. These attacks target the vulnerabilities of various computer resources, such as, the operating system, web browsers, toolbars, etc. along with the susceptibility of the users due to lack of awareness about the possible scams. The existing solutions suffer various drawbacks. The website phishing solutions...

متن کامل

Phinding Phish: An Evaluation of Anti-Phishing Toolbars

There are currently dozens of freely available tools to combat phishing and other web-based scams, many of which are web browser extensions that warn users when they are browsing a suspected phishing site. We developed an automated test bed for testing antiphishing tools. We used 200 verified phishing URLs from two sources and 516 legitimate URLs to test the effectiveness of 10 popular anti-phi...

متن کامل

Token Based Security for Prevention of Phishing Attack at Client Side

Phishing is an electronic identity theft in which the attacker uses a combination of social engineering techniques and web spoofing techniques to decept a user into revealing sensitive information. The literature addresses this issue extensively and presents a number of solutions, which are either client based or server based. Generally client based solutions have an upper hand over the server ...

متن کامل

On the Effectiveness of Techniques to Detect Phishing Sites

Abstract. Phishing is an electronic online identity theft in which the attackers use a combination of social engineering and web site spoofing techniques to trick a user into revealing confidential information. This information is typically used to make an illegal economic profit (e.g., by online banking transactions, purchase of goods using stolen credentials, etc.). Although simple, phishing ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012