Harvesting SSL Certificate Data to Identify Web-Fraud
Cryptography and Security
2015-03-13 v4 Networking and Internet Architecture
Abstract
Web-fraud is one of the most unpleasant features of today's Internet. Two well-known examples of fraudulent activities on the web are phishing and typosquatting. Their effects range from relatively benign (such as unwanted ads) to downright sinister (especially, when typosquatting is combined with phishing). This paper presents a novel technique to detect web-fraud domains that utilize HTTPS. To this end, we conduct the first comprehensive study of SSL certificates. We analyze certificates of legitimate and popular domains and those used by fraudulent ones. Drawing from extensive measurements, we build a classifier that detects such malicious domains with high accuracy.
Keywords
Cite
@article{arxiv.0909.3688,
title = {Harvesting SSL Certificate Data to Identify Web-Fraud},
author = {Mishari Al Mishari and Emiliano De Cristofaro and Karim El Defrawy and Gene Tsudik},
journal= {arXiv preprint arXiv:0909.3688},
year = {2015}
}
Comments
To appear in the International Journal of Network Security