Online Detection and Prevention of Phishing Attacks (Invited Paper)
Chuanxiong Guo · 2006
isanewtypeofnetwork attack wherethe attacker creates areplica ofanexisting Web pagetofool users (e.g., byusingspecially designed e-mails orinstant messages) intosubmitting personal, financial, orpassword datatowhat theythinkistheir service provides' Web site. Inthis paper, we propose a newend-host basedanti-phishing algorithm, which we callLinkGuard, byutilizing thegeneric characteristics of thehyperlinks inphishing attacks. Thesecharacteristics are derived byanalyzing thephishing dataarchive provided bythe Anti-Phishing WorkingGroup(APWG).Because itisbasedon thegeneric characteristics ofphishing attacks, LinkGuard can detect notonlyknownbutalsounknownphishing attacks. We haveimplemented LinkGuard inWindowsXP.Ourexperiments verified thatLinkGuard iseffective todetect andprevent both knownandunknownphishing attacks withminimal false negatives. LinkGuard successfully detects 195outofthe203phishing attacks. Ourexperiments alsoshowedthatLinkGuard islightweighted andcandetect andprevent phishing attacks inrealtime. IndexTerms-Networksecurity, Phishing attacks, Hyperlink, LinkGuard algorithm. I.INTRODUCTION Theword'Phishing' initially emerged in1990s. Theearly hackers often use'ph' toreplace 'f'toproduce newwordsin thehacker's community, since theyusually hackbyphones. Phishing isanewwordproduced from'fishing', itrefers to theactthattheattacker allure users tovisit a faked Web site bysending themfaked e-mails (orinstant messages), and stealthily getvictim's personal information suchasusername, password, andnational security ID,etc.Theseinformation thencanbeusedforfuture target advertisements oreven identity theft attacks (e.g., transfer moneyfromvictims' bank account).