Abstract

User ignorance towards the use of communication services like Instant Messengers, emails, websites, social networks etc. is becoming the biggest advantage for phishers. It is required to create technical awareness in users by educating them to create a phishing detection application which would generate phishing alerts for the user so that phishing messages are not ignored. The lack of basic security features to detect and prevent phishing has had a profound effect on the IM clients, as they lose their faith in e-banking and e-commerce transactions, which will have a disastrous impact on the corporate and banking sectors and businesses which rely heavily on the internet. Very little research contributions were available in for phishing detection in Instant messengers. A context based, dynamic and intelligent phishing detection methodology in IMs is proposed, to analyze and detect phishing in Instant Messages with relevance to domain ontology (OBIE) and utilizes the Classification based on Association (CBA) for generating phishing rules and alerting the victims. A PDS Monitoring system algorithm is used to identify the phishing activity during exchange of messages in IMs, with high ratio of precision and recall. The results have shown improvement by the increased percentage of precision and recall when compared to the existing methods.

Highlights

  • Instant messengers (IMs) have become an integral part of today’s state of the art communication system with the latest gizmos, smartphones, tablets, laptops etc., becoming affordable and gaining popularity globally

  • If a new phishing word is identified based on threshold values based on frequently occurring words during chatting or a new phishing domain is discovered, these phishing words are appended to the Phishing Word DB (PWDB)

  • The system workflow of the PDS monitoring algorithm initiates the steps to capture the phishing words from instant messages that are exchanged between the chatters through pre-defined phishing rules of Table 3.1 through Classification based on Association Rules (CBA) and Domain Ontology

Read more

Summary

INTRODUCTION

Instant messengers (IMs) have become an integral part of today’s state of the art communication system with the latest gizmos, smartphones, tablets, laptops etc., becoming affordable and gaining popularity globally. With the large number of additional features available in the Instant Messengers, the potential areas for attack have increased, as there are no concrete methodologies to counter Phishing attacks This could lead to a profound effect on a phishing victim as he or she loses the trust in internet banking and e-commerce transactions by falling prey into disclosing confidential account details to the phisher’s devious tricks. Avoiding ambiguity over the relevance of the identified phishing words is the main motive behind this work in order to enhance the instant messaging system performance This could be done by identifying the context behind chatting messages in order to reduce the percentage of both false positives and false negatives. It provides directions for future enhancements in this research area

RELATED WORK
System Architecture
System Workflow
12. Display message
The OBIE Architecture
Rule generation with CAR
Applying CBA for Phishing Rule generation
RESULTS AND OBSERVATIONS
CONCLUSIONS
Future Work
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call