中文
相关论文

相关论文: PhishReplicant: A Language Model-based Approach to…

200 篇论文

Now-a-days, cyberattacks are increasing at an unprecedented rate. Phishing is a social engineering attack which has a massive global impact, destroying the financial and economic value of corporations, government sectors and individuals. In…

密码学与安全 · 计算机科学 2022-05-12 Kalaharsha Pagadala

DNS is important in nearly all interactions on the Internet. All large DNS operators use IP anycast, announcing servers in BGP from multiple physical locations to reduce client latency and provide capacity. However, DNS is easy to spoof:…

密码学与安全 · 计算机科学 2020-11-30 Lan Wei , John Heidemann

Domain Name Service is a trusted protocol made for name resolution, but during past years some approaches have been developed to use it for data transfer. DNS Tunneling is a method where data is encoded inside DNS queries, allowing…

密码学与安全 · 计算机科学 2020-06-16 Franco Palau , Carlos Catania , Jorge Guerra , Sebastian Garcia , Maria Rigaki

In recent years, malware with tunneling (or: covert channel) capabilities is on the rise. While malware research led to several methods and innovations, the detection and differentiation of malware solely based on its DNS tunneling features…

密码学与安全 · 计算机科学 2025-11-20 Denis Petrov , Pascal Ruffing , Sebastian Zillien , Steffen Wendzel

The security of passwords depends on a thorough understanding of the strategies used by attackers. Unfortunately, real-world adversaries use pragmatic guessing tactics like dictionary attacks, which are difficult to simulate in password…

密码学与安全 · 计算机科学 2022-08-16 Fangyi Yu , Miguel Vargas Martin

The proliferation of phishing sites and emails poses significant challenges to existing cybersecurity efforts. Despite advances in malicious email filters and email security protocols, problems with oversight and false positives persist.…

密码学与安全 · 计算机科学 2024-08-26 Takashi Koide , Naoki Fukushi , Hiroki Nakano , Daiki Chiba

Phishing attacks trick victims into disclosing sensitive information. To counter rapidly evolving attacks, we must explore machine learning and deep learning models leveraging large-scale data. We discuss models built on different kinds of…

密码学与安全 · 计算机科学 2022-05-17 Dinil Mon Divakaran , Adam Oest

Phishing attacks threaten online users, often leading to data breaches, financial losses, and identity theft. Traditional phishing detection systems struggle with high false positive rates and are usually limited by the types of attacks…

密码学与安全 · 计算机科学 2025-05-01 Sneha Baskota

Domain generation algorithms (DGAs) are commonly leveraged by malware to create lists of domain names which can be used for command and control (C&C) purposes. Approaches based on machine learning have recently been developed to…

Various families of malware use domain generation algorithms (DGAs) to generate a large number of pseudo-random domain names to connect to a command and control (C&C) server. In order to block DGA C&C traffic, security organizations must…

密码学与安全 · 计算机科学 2016-11-04 Jonathan Woodbridge , Hyrum S. Anderson , Anjum Ahuja , Daniel Grant

Phishing emails are the first step for many of today's attacks. They come with a simple hyperlink, request for action or a full replica of an existing service or website. The goal is generally to trick the user to voluntarily give away his…

密码学与安全 · 计算机科学 2020-04-22 Suhail Paliath , Mohammad Abu Qbeitah , Monther Aldwairi

SMS phishing, also known as "smishing", is a growing threat that tricks users into disclosing private information or clicking into URLs with malicious content through fraudulent mobile text messages. In recent past, we have also observed a…

密码学与安全 · 计算机科学 2024-02-16 Ashfak Md Shibli , Mir Mehedi A. Pritom , Maanak Gupta

Phishing attacks are a significant societal threat, disproportionately harming vulnerable populations and eroding trust in essential digital services. Current defenses are often reactive, failing against modern evasive tactics like cloaking…

密码学与安全 · 计算机科学 2026-01-23 Daiki Chiba , Hiroki Nakano , Takashi Koide

Voice phishing (vishing) remains a persistent threat in cybersecurity, exploiting human trust through persuasive speech. While machine learning (ML)-based classifiers have shown promise in detecting malicious call transcripts, they remain…

密码学与安全 · 计算机科学 2025-07-23 Wenhao Li , Selvakumar Manickam , Yung-wey Chong , Shankar Karuppayah

This paper explores the possibility of using ChatGPT to develop advanced phishing attacks and automate their large-scale deployment. We make ChatGPT generate the following parts of a phishing attack: i) cloning a targeted website, ii)…

密码学与安全 · 计算机科学 2023-09-20 Nils Begou , Jeremy Vinoy , Andrzej Duda , Maciej Korczynski

Phishing campaigns involve adversaries masquerading as trusted vendors trying to trigger user behavior that enables them to exfiltrate private data. While URLs are an important part of phishing campaigns, communicative elements like text…

密码学与安全 · 计算机科学 2026-05-14 Fengchao Chen , Tingmin Wu , Van Nguyen , Carsten Rudolph

There is a continuous increase in the sophistication that modern malware exercise in order to bypass the deployed security mechanisms. A typical approach to evade the identification and potential takedown of a botnet command and control…

密码学与安全 · 计算机科学 2019-09-17 Constantinos Patsakis , Fran Casino , Vasilios Katos

In a spoofing attack, a malicious actor impersonates a legitimate user to access or manipulate data without authorization. The vulnerability of cryptographic security mechanisms to compromised user credentials motivates spoofing attack…

信号处理 · 电气工程与系统科学 2024-01-17 Tien Ngoc Ha , Daniel Romero

In this paper, we uncover the essential features of websites that allow intelligent models to distinguish between phishing and legitimate sites. Phishing websites are those that are made with a similar user interface and a near similar…

社会与信息网络 · 计算机科学 2022-05-09 Arash Negahdari Kia , Finbarr Murphy , Zahra Dehghani Mohammadabadi , Parisa Shamsi

Spear Phishing is a type of cyber-attack where the attacker sends hyperlinks through email on well-researched targets. The objective is to obtain sensitive information by imitating oneself as a trustworthy website. In recent times, deep…

密码学与安全 · 计算机科学 2022-11-17 Sharif Amit Kamran , Shamik Sengupta , Alireza Tavakkoli