Skip to main navigation Skip to search Skip to main content

A Multistage Framework to Defend Against Phishing Attacks

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

Phishing scams pose a serious threat to end-users and commercial institutions alike. E-mail continues to be the favorite vehicle to perpetrate such scams, mainly due to its widespread use combined with the ability to easily spoof them. Several approaches, both generic and specialized, have been proposed to address this growing problem. However, phishing techniques, growing in ingenuity as well as sophistication, render these solutions weak. To overcome these limitations, we propose a multistage framework - the first stage aims at detecting phishing based on their semantic and structural properties, whereas in the second stage we propose a proactive technique based on a challenge-response technique to establish the authenticity of a Web site. Using live e-mail data, we demonstrate that our approach with these two stages is able to detect a wider range of phishing attacks than existing schemes. Also, our performance analysis study shows that the implementation overhead introduced by our tool is negligibly small.

Original languageEnglish
Title of host publicationCyber Crime
Subtitle of host publicationConcepts, Methodologies, Tools and Applications
PublisherIGI Global
Pages245-262
Number of pages18
Volume1-3
ISBN (Electronic)9781613503249
ISBN (Print)9781613503232
DOIs
StatePublished - Nov 30 2011

Fingerprint

Dive into the research topics of 'A Multistage Framework to Defend Against Phishing Attacks'. Together they form a unique fingerprint.

Cite this