Classification of Web Phishing Kits for early detection by platform providers

10/15/2022
by   Andrea Venturi, et al.
0

Phishing kits are tools that dark side experts provide to the community of criminal phishers to facilitate the construction of malicious Web sites. As these kits evolve in sophistication, providers of Web-based services need to keep pace with continuous complexity. We present an original classification of a corpus of over 2000 recent phishing kits according to their adopted evasion and obfuscation functions. We carry out an initial deterministic analysis of the source code of the kits to extract the most discriminant features and information about their principal authors. We then integrate this initial classification through supervised machine learning models. Thanks to the ground-truth achieved in the first step, we can demonstrate whether and which machine learning models are able to suitably classify even the kits adopting novel evasion and obfuscation techniques that were unseen during the training phase. We compare different algorithms and evaluate their robustness in the realistic case in which only a small number of phishing kits are available for training. This paper represents an initial but important step to support Web service providers and analysts in improving early detection mechanisms and intelligence operations for the phishing kits that might be installed on their platforms.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/04/2018

Qos-Based Web Service Discovery And Selection Using Machine Learning

In service computing, the same target functions can be achieved by multi...
research
11/10/2022

Training and Serving Machine Learning Models at Scale

In recent years, Web services are becoming more and more intelligent (e....
research
06/09/2023

Detecting Phishing Sites Using ChatGPT

The rise of large language models (LLMs) has had a significant impact on...
research
03/04/2022

In the Service of Online Order: Tackling Cyber-Bullying with Machine Learning and Affect Analysis

One of the burning problems lately in Japan has been cyber-bullying, or ...
research
08/20/2018

FedMark: A Marketplace for Federated Data on the Web

The Web of Data (WoD) has experienced a phenomenal growth in the past. T...
research
07/08/2021

Data-Driven Extract Method Recommendations: A Study at ING

The sound identification of refactoring opportunities is still an open p...
research
02/06/2018

Astrophysicists and physicists as creators of ArXiv-based commenting resources for their research communities. An initial survey

This paper conveys the outcomes of what results to be the first, though ...

Please sign up or login with your details

Forgot password? Click here to reset