AuntieTuna: Personalized Content-based Phishing Detection

Calvin Ardi, John Heidemann · 2016

Phishing sites masquerade as copies of legitimate sites ("targets") to fool people into sharing sensitive information that can then be used for fraud.Current phishing defenses can be ineffective, with training ignored, blacklists of discovered, bad sites too slow to pick up new threats, and whitelists of knowngood sites too limiting.We have developed a new technique that automatically builds personalized lists of target sites (candidates that may be copied by phish) and then tests sites as a user browses them.Our approach uses cryptographic hashing of each page's rendered Document Object Model (DOM), providing a zero false positive rate and identifying more than half of detectable phish in a controlled study.Since each user develops a customized list of target sites, our approach presents a diverse defense against phishers.We have prototyped our approach as a Chrome browser plugin called AuntieTuna, emphasizing usability through automated and simple manual addition of target sites and clean reports of potential phish that include context about the targeted site.AuntieTuna does not slow web browsing time and presents alerts on phishing pages before users can divulge information.

Read the paper · More papers on PaperTik