论文标题
对免费网络托管域上托管的网络钓鱼网站的大规模分析
A Large-Scale Analysis of Phishing Websites Hosted on Free Web Hosting Domains
论文作者
论文摘要
免费的网站建筑服务(FWB)为个人提供了一种成本效益,方便的方式来创建网站,而无需高级技术知识或编码技能。但是,恶意演员经常滥用这些服务来接待网络钓鱼网站。在这项工作中,我们提出了一种可扩展的框架,可以连续识别使用FWB创建的网络钓鱼网站。使用Freephish,我们能够检测和表征超过31.4k的网络钓鱼URL,这些网址是使用17个独特的免费网站构建器服务创建的,并在Twitter和Facebook上共享了六个月。我们发现,FWB为攻击者提供了几个功能,这些功能使其更容易按大规模创建和维护网络钓鱼网站,同时逃避反向钓鱼的对策。我们的研究表明,与常规(自托管)网站相比,针对FWB网络钓鱼攻击的抗网络列表和浏览器保护工具的覆盖范围和高检测时间明显降低和较高的检测时间。尽管我们对这些攻击的迅速披露有助于一些FWB删除这些攻击,但我们发现其他几个人在撤职方面缓慢或没有直接将其删除,而Twitter和Facebook也是如此。最后,我们还提供弗里斯(Freephish)作为免费的铬网络扩展名,可用于防止最终用户访问潜在的基于FWB的网络钓鱼攻击。
Free Website Building services (FWBs) provide individuals with a cost-effective and convenient way to create a website without requiring advanced technical knowledge or coding skills. However, malicious actors often abuse these services to host phishing websites. In this work, we propose FreePhish, a scalable framework to continuously identify phishing websites that are created using FWBs. Using FreePhish, we were able to detect and characterize more than 31.4K phishing URLs that were created using 17 unique free website builder services and shared on Twitter and Facebook over a period of six months. We find that FWBs provide attackers with several features that make it easier to create and maintain phishing websites at scale while simultaneously evading anti-phishing countermeasures. Our study indicates that anti-phishing blocklists and browser protection tools have significantly lower coverage and high detection time against FWB phishing attacks when compared to regular (self-hosted) phishing websites. While our prompt disclosure of these attacks helped some FWBs to remove these attacks, we found several others who were slow at removal or did not remove them outright, with the same also being true for Twitter and Facebook. Finally, we also provide FreePhish as a free Chromium web extension that can be utilized to prevent end-users from accessing potential FWB-based phishing attacks.