English

Harvesting SSL Certificate Data to Identify Web-Fraud

Cryptography and Security 2015-03-13 v4 Networking and Internet Architecture

Abstract

Web-fraud is one of the most unpleasant features of today's Internet. Two well-known examples of fraudulent activities on the web are phishing and typosquatting. Their effects range from relatively benign (such as unwanted ads) to downright sinister (especially, when typosquatting is combined with phishing). This paper presents a novel technique to detect web-fraud domains that utilize HTTPS. To this end, we conduct the first comprehensive study of SSL certificates. We analyze certificates of legitimate and popular domains and those used by fraudulent ones. Drawing from extensive measurements, we build a classifier that detects such malicious domains with high accuracy.

Keywords

Cite

@article{arxiv.0909.3688,
  title  = {Harvesting SSL Certificate Data to Identify Web-Fraud},
  author = {Mishari Al Mishari and Emiliano De Cristofaro and Karim El Defrawy and Gene Tsudik},
  journal= {arXiv preprint arXiv:0909.3688},
  year   = {2015}
}

Comments

To appear in the International Journal of Network Security

R2 v1 2026-06-21T13:48:30.534Z