Detection and Prevention of Phishing Attacks on Banking Website

Prajwal Jaswal, Shweta Gaur Sharma, Naveen Bindra, Cettymalla Rama Krishna · 2022

Phishing is a type of social engineering attack to trick users to reveal their personal information. Attackers deploy malicious software by creating phished websites which seems to be exactly like genuine websites. Given the dramatically increasing number of phishing attacks on banking websites, it becomes crucial to detect and prevent the users from these attacks. Unfortunately, humans are not adept at performing the security checks necessary for secure website identification, and one mistake can lead to a user’s entire online account being compromised. In this paper, we propose a novel framework for detection and prevention of phishing attacks on banking website. Our proposed framework is specific towards protecting the banking website against phishing attacks. For client side, we develop a plugin to validate the legitimacy of banking Uniform Resource Locator (URL). For bank side, we develop a web portal which acts as an interface by the bank representative to add, delete, and edit URLs in the database. On server side, an administrator is responsible for managing the complete database such as maintenance of the web portal, credential generation for bank representative, etc. The results show that our proposed framework effectively detects and prevents the phishing attacks on banking website with a best case time complexity of $\Omega(1)$ and worst case time complexity of ON(if the URL is in database) and the best case time complexity of $\Omega(\mathrm{N})$ and worst case time complexity of O(N$*$M) (if the URL is not in database and contain malicious keywords).

Read the paper · More papers on PaperTik