中文
相关论文

相关论文: Harvesting SSL Certificate Data to Identify Web-Fr…

200 篇论文

Phishing is considered to be one of the most prevalent cyber-attacks because of its immense flexibility and alarmingly high success rate. Even with adequate training and high situational awareness, it can still be hard for users to…

密码学与安全 · 计算机科学 2020-05-15 Orestis Christou , Nikolaos Pitropakis , Pavlos Papadopoulos , Sean McKeown , William J. Buchanan

Malicious URL, a.k.a. malicious website, is a common and serious threat to cybersecurity. Malicious URLs host unsolicited content (spam, phishing, drive-by exploits, etc.) and lure unsuspecting users to become victims of scams (monetary…

机器学习 · 计算机科学 2019-08-22 Doyen Sahoo , Chenghao Liu , Steven C. H. Hoi

Domain squatting is a common adversarial practice where attackers register domain names that are purposefully similar to popular domains. In this work, we study a specific type of domain squatting called "combosquatting," in which attackers…

The current implementation of TLS involves your browser displaying a padlock, and a green bar, after successfully verifying the digital signature on the TLS certificate. Proposed is a solution where your browser's response to successful…

密码学与安全 · 计算机科学 2018-04-13 Joseph Kilcullen

Phishing is the most prevalent type of cyber-attack today and is recognized as the leading source of data breaches with significant consequences for both individuals and corporations. Web-based phishing attacks are the most frequent with…

密码学与安全 · 计算机科学 2025-02-20 Muhammad Fahad Zia , Sri Harish Kalidass

Phishing is an increasingly sophisticated method to steal personal user information using sites that pretend to be legitimate. In this paper, we take the following steps to identify phishing URLs. First, we carefully select lexical features…

密码学与安全 · 计算机科学 2016-11-18 Anh Le , Athina Markopoulou , Michalis Faloutsos

Flawed TLS certificates are not uncommon on the Internet. While they signal a potential issue, in most cases they have benign causes (e.g., misconfiguration or even deliberate deployment). This adds fuzziness to the decision on whether to…

密码学与安全 · 计算机科学 2022-07-26 Martin Ukrop , Lydia Kraus , Vashek Matyas

If two or more identical HTTPS clients, located at different geographic locations (regions), make an HTTPS request to the same domain (e.g. example.com), on the same day, will they receive the same HTTPS security guarantees in response? Our…

密码学与安全 · 计算机科学 2020-10-21 Eman Salem Alashwali , Pawel Szalachowski , Andrew Martin

The level of trust accorded to certification authorities has been decreasing over the last few years as several cases of misbehavior and compromise have been observed. Log-based approaches, such as Certificate Transparency, ensure that…

密码学与安全 · 计算机科学 2016-01-06 Laurent Chuat , Pawel Szalachowski , Adrian Perrig , Ben Laurie , Eran Messeri

Cloud providers' support for network evasion techniques that misrepresent the server's domain name is more prevalent than previously believed, which has serious implications for security and privacy due to the reliance on domain names in…

密码学与安全 · 计算机科学 2023-07-18 Blake Anderson , David McGrew

Web-based phishing attacks nowadays exploit popular cloud web hosting services and apps such as Google Sites and Typeform for hosting their attacks. Since these attacks originate from reputable domains and IP addresses of the cloud…

密码学与安全 · 计算机科学 2022-10-31 Birendra Jha , Medha Atre , Ashwini Rao

We present new analytic techniques for inferring HTTP semantics from passive observations of HTTPS that can infer the value of important fields including the status-code, Content-Type, and Server, and the presence or absence of several…

密码学与安全 · 计算机科学 2018-05-30 Blake Anderson , Andrew Chi , Scott Dunlop , David McGrew

Phishing and spear-phishing are typical examples of masquerade attacks since trust is built up through impersonation for the attack to succeed. Given the prevalence of these attacks, considerable research has been conducted on these…

密码学与安全 · 计算机科学 2019-11-05 Avisha Das , Shahryar Baki , Ayman El Aassal , Rakesh Verma , Arthur Dunbar

Phishing websites remain a persistent cybersecurity threat by mimicking legitimate sites to steal sensitive user information. Existing machine learning-based detection methods often rely on supervised learning with labeled data, which not…

密码学与安全 · 计算机科学 2025-10-08 Wenhao Li , Selvakumar Manickam , Yung-Wey Chong , Shankar Karuppayah , Priyadarsi Nanda , Binyong Li

Recently, we can observe a significant increase of the phishing attacks in the Internet. In a typical phishing attack, the attacker sets up a malicious website that looks similar to the legitimate website in order to obtain the end-users'…

密码学与安全 · 计算机科学 2025-08-14 Zijiang Yang

Phishing continues to pose a significant cybersecurity threat. While blocklists currently serve as a primary defense, due to their reactive, passive nature, these delayed responses leave phishing websites operational long enough to harm…

密码学与安全 · 计算机科学 2025-04-18 Kyungchan Lim , Raffaele Sommese , Mattis Jonker , Ricky Mok , kc claffy , Doowon Kim

Internet technology is so pervasive today, for example, from online social networking to online banking, it has made people's lives more comfortable. Due the growth of Internet technology, security threats to systems and networks are…

密码学与安全 · 计算机科学 2017-05-30 B. B. Gupta , Nalin Asanka Gamagedara Arachchilage , Konstantinos E. Psannis

The widespread accessibility of the Internet has led to a surge in online fraudulent activities, underscoring the necessity of shielding users' sensitive information from cybercriminals. Phishing, a well-known cyberattack, revolves around…

密码学与安全 · 计算机科学 2024-01-17 Aditya Kulkarni , Vivek Balachandran , Dinil Mon Divakaran , Tamal Das

Recently, the development and implementation of phishing attacks require little technical skills and costs. This uprising has led to an ever-growing number of phishing attacks on the World Wide Web. Consequently, proactive techniques to…

密码学与安全 · 计算机科学 2020-11-09 Chidimma Opara , Bo Wei , Yingke Chen

The web is experiencing an explosive growth in the last years. New technologies are introduced at a very fast-pace with the aim of narrowing the gap between web-based applications and traditional desktop applications. The results are web…

密码学与安全 · 计算机科学 2015-07-14 Alfredo De Santis , Giancarlo De Maio , Umberto Ferraro Petrillo