1. Leverage Website Favicon to Detect Phishing Websites
- Author
-
Jeffrey Soon-Fatt Choo, Kelvin S. C. Yong, Kang Leng Chiew, and San Nah Sze
- Subjects
Leverage (finance) ,Article Subject ,Computer Networks and Communications ,Computer science ,Phishing attack ,020206 networking & telecommunications ,02 engineering and technology ,Phishing ,World Wide Web ,Cybercrime ,Domain name ,Favicon ,lcsh:Technology (General) ,0202 electrical engineering, electronic engineering, information engineering ,lcsh:T1-995 ,020201 artificial intelligence & image processing ,False positive rate ,Internet users ,lcsh:Science (General) ,lcsh:Q1-390 ,Information Systems - Abstract
Phishing attack is a cybercrime that can lead to severe financial losses for Internet users and entrepreneurs. Typically, phishers are fond of using fuzzy techniques during the creation of a website. They confuse the victim by imitating the appearance and content of a legitimate website. In addition, many websites are vulnerable to phishing attacks, including financial institutions, social networks, e-commerce, and airline websites. This paper is an extension of our previous work that leverages the favicon with Google image search to reveal the identity of a website. Our identity retrieval technique involves an effective mathematical model that can be used to assist in retrieving the right identity from the many entries of the search results. In this paper, we introduced an enhanced version of the favicon-based phishing attack detection with the introduction of the Domain Name Amplification feature and incorporation of addition features. Additional features are very useful when the website being examined does not have a favicon. We have collected a total of 5,000 phishing websites from PhishTank and 5,000 legitimate websites from Alexa to verify the effectiveness of the proposed method. From the experimental results, we achieved a 96.93% true positive rate with only a 4.13% false positive rate.
- Published
- 2018