Ne Needle in a Haystack: : Tracking Do Down Elite Ph Phishing g Dom Domains in the Wild
Ke Tian, Steve T.K. Jan, Hang Hu, Danfeng Yao, Gang Wang Computer Science, Virginia Tech
Ne Needle in a Haystack: : Tracking Do Down Elite Ph Phishing g - - PowerPoint PPT Presentation
Ne Needle in a Haystack: : Tracking Do Down Elite Ph Phishing g Dom Domains in the Wild Ke Tian, Steve T.K. Jan , Hang Hu, Danfeng Yao, Gang Wang Computer Science, Virginia Tech Phishing is a Big Th Threat Phishing: fraudulent attempt
Ne Needle in a Haystack: : Tracking Do Down Elite Ph Phishing g Dom Domains in the Wild
Ke Tian, Steve T.K. Jan, Hang Hu, Danfeng Yao, Gang Wang Computer Science, Virginia Tech
Phishing is a Big Th Threat
2
Yahoo Data Breach in 2014 Affected 500 Million Yahoo! User Account Ubiquiti Networks Lost $46.7M dollar to scammers in 2015
3 http://178.128.85.7/banks/National URL not relate to Paypal: Phishing http://account-updates-center-service.beedoces.com.br
Some Some P Phishing W Websites a are E Easy t to T
4 http://178.128.85.7/banks/National URL not include domain name: Phishing http://account-updates-center-service.beedoces.com.br
Some Some P Phishing W Websites a are E Easy t to T
http://178.128.85.7/banks/National
Mor More Sop Sophisticated P Phishing E Examp mple
different characters look alike
5 http://www.apple.com http://www.apple.com Different Char
Mor More Sop Sophisticated P Phishing E Examp mple
different characters look alike
6 http://www.apple.com http://www.apple.com Different Char http://get.adoḅe.com/es/flashplayer
Ho How w can an we e system ematic tically ally cap aptur ture e thes these e so sophisticated phish shing g websi sites s in practice?
7
Th This Study
8
Ou Outline
9
Detec ecti tion n Metho thodo dology gy
10 Squatting Domains: 657,663 Phishing: 1,741 Confirmed: Web 857 Mobile: 908 DNS Records: 224,810,532 Popular brands: 702 Squatting domain detection Phishing classifier Manually check
Detec ect t Squa quatti ting ng Domain
1. Homograph: Look similar to target domain 2. Bits: Flip a bit of target domain 3. Typo: Mimic the incorrectly typed of target domain 4. Combo: Connect target domain with other strings 5. WrongTLD: Different TLD of target domain 11 facebook-stroty.com facebook.audi fcaebook.com facebnok.com faceb00k.com facebook.com facebook.com
Detec ect t Squa quatti ting ng Domain
12 pricelin.com Squattting Domain priceline.com Original Brand
Re-direct
Ph Phis ishin ing Clas lassif ifier ier
13
La Layou
Obfuscation
14 Target Brand Phishing Website
Be detected by existing methods Not be detected by existing methods
<script> String.fromCharCode(50) + “a” + …. <title> Log in to your PayPal </title>
Be detected by keyword- similarly based methods
<title> Log in to your PayPa1 </title>
St Stri ring/Cod /Code O Obfuscation
detection
15 Phishing HTML Target Brand HTML <title> Log in to your PayPal </title>
String Obfuscation Code Obfuscation
Ou Our Desi sign gn
16 Keyword list: Paypol Email passward …… Keyword list: Paypal Email password ……
Google OCR NLTK spell check
Ou Our Desi sign gn Cont.
17
Gr Ground Truth th Evalu aluatio tion
18 Classifier False Positive False Negative AUC NaïveBayes 0.5 0.05 0.64 KNN 0.04 0.1 0.92 Random Forest 0.03 0.06 0.97
Random Forest is highly accurate
Ou Outline
19
DNS Records: 224,810,532, Popular brands: 702 20 Squatting domains: 657,663 Detected Phishing pages: 1,741
Confirmed phishing pages
Detec ecti tion n in n Practi tice
Confirmed phishing pages
Web only: 267 Phishing on Mobile and Web: 590 Mobile only: 318 Confirmed phishing pages
Squatting phishing websites indeed exist More phishing websites on mobile
Can Current Blacklists Detect Th Them?
21
200 400 600 800 1000 1200 PhishTank VirusTotal eCrimeX Evaded Blacklists
# of Pages
Over 90 % live
Reported them
Existing blacklists/tools are not capable to capture squatting phishing yet
Sq Squatting D Doma
Types
22
100 200 300 400 500 600 Homograph Bits Typo Combo WrongTLD
# of pages Web Mobile
Ex Exampl ple Study: udy: Ube ber
23 go-uberfreight.com Target Domain Squatting Domain freight.uber.com
Ex Exampl ple Study: udy: Of Offi fice 365
24 Target Domain Squatting Domain
Con Conclusion
25
26
27
Ev Evasions in Squatting Phishing
28
Obfuscation is common to squatting phishing.
IP IP Locatio tion
countries.
29
Fa False Positive Prediction
30 http://paypal.me