Design and evaluation of the highly insidious extreme phishing attacks. Issue 70 (September 2017)
- Record Type:
- Journal Article
- Title:
- Design and evaluation of the highly insidious extreme phishing attacks. Issue 70 (September 2017)
- Main Title:
- Design and evaluation of the highly insidious extreme phishing attacks
- Authors:
- Zhao, Rui
John, Samantha
Karas, Stacy
Bussell, Cara
Roberts, Jennifer
Six, Daniel
Gavett, Brandon
Yue, Chuan - Abstract:
- Abstract: One of the most severe and challenging threats to Internet security is phishing, which uses spoofed websites to steal users' passwords and online identities. Phishers mainly use spoofed emails or instant messages to lure users to the phishing websites. A spoofed email or instant message provides the first-layer context to entice users to click on a phishing URL, and the phishing website further provides the second-layer context with the look and feel similar to a targeted legitimate website to lure users to submit their login credentials. In this paper, we focus on the second-layer context to explore the extreme of phishing attacks; we explore the feasibility of creating extreme phishing attacks that have the almost identical look and feel as those of the targeted legitimate websites, and evaluate the effectiveness of such phishing attacks. We design and implement a phishing toolkit that can support both the traditional phishing and the newly emergent Web Single Sign-On (SSO) phishing; our toolkit can automatically construct unlimited levels of phishing webpages in real time based on user interactions. We design and perform a user study with 194 participants to evaluate the effectiveness of the phishing attacks constructed from this toolkit. The results demonstrate that extreme phishing attacks are indeed highly effective and insidious as over 90% of the participants became the "victims". It is reasonable to assume that extreme phishing attacks will be widelyAbstract: One of the most severe and challenging threats to Internet security is phishing, which uses spoofed websites to steal users' passwords and online identities. Phishers mainly use spoofed emails or instant messages to lure users to the phishing websites. A spoofed email or instant message provides the first-layer context to entice users to click on a phishing URL, and the phishing website further provides the second-layer context with the look and feel similar to a targeted legitimate website to lure users to submit their login credentials. In this paper, we focus on the second-layer context to explore the extreme of phishing attacks; we explore the feasibility of creating extreme phishing attacks that have the almost identical look and feel as those of the targeted legitimate websites, and evaluate the effectiveness of such phishing attacks. We design and implement a phishing toolkit that can support both the traditional phishing and the newly emergent Web Single Sign-On (SSO) phishing; our toolkit can automatically construct unlimited levels of phishing webpages in real time based on user interactions. We design and perform a user study with 194 participants to evaluate the effectiveness of the phishing attacks constructed from this toolkit. The results demonstrate that extreme phishing attacks are indeed highly effective and insidious as over 90% of the participants became the "victims". It is reasonable to assume that extreme phishing attacks will be widely adopted and deployed in the future, and we call for a collective effort to effectively defend against them. … (more)
- Is Part Of:
- Computers & security. Issue 70(2017)
- Journal:
- Computers & security
- Issue:
- Issue 70(2017)
- Issue Display:
- Volume 70, Issue 70 (2017)
- Year:
- 2017
- Volume:
- 70
- Issue:
- 70
- Issue Sort Value:
- 2017-0070-0070-0000
- Page Start:
- 634
- Page End:
- 647
- Publication Date:
- 2017-09
- Subjects:
- Web -- Phishing -- Susceptibility -- Single Sign-On -- Toolkit
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2017.08.008 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 7021.xml