The rise in phishing attacks via e-mail and short message service (SMS) has not slowed down at all. The first thing we need to do to combat the ever-increasing number of phishing attacks is to collect and characterize more phishing cases that reach end users. Without understanding these characteristics, anti-phishing countermeasures cannot evolve. In this study, we propose an approach using Twitter as a new observation point to immediately collect and characterize phishing cases via e-mail and SMS that evade countermeasures and reach users. Specifically, we propose CrowdCanary, a system capable of structurally and accurately extracting phishing information (e.g., URLs and domains) from tweets about phishing by users who have actually discovered or encountered it. In our three months of live operation, CrowdCanary identified 35,432 phishing URLs out of 38,935 phishing reports. We confirmed that 31,960 (90.2%) of these phishing URLs were later detected by the anti-virus engine, demonstrating that CrowdCanary is superior to existing systems in both accuracy and volume of threat extraction. We also analyzed users who shared phishing threats by utilizing the extracted phishing URLs and categorized them into two distinct groups - namely, experts and non-experts. As a result, we found that CrowdCanary could collect information that is specifically included in non-expert reports, such as information shared only by the company brand name in the tweet, information about phishing attacks that we find only in the image of the tweet, and information about the landing page before the redirect.
翻译:通过电子邮件和短信服务(SMS)进行的网络钓鱼攻击的数量并未减缓。为了应对日益增多的网络钓鱼攻击,我们首先需要收集并刻画更多触及终端用户的钓鱼案例。若不理解这些特征,反钓鱼对策便无法演进。在本研究中,我们提出一种利用Twitter作为新观测点的方法,以即时收集并刻画那些规避了防御措施并到达用户的电子邮件及SMS钓鱼案例。具体而言,我们提出了CrowdCanary系统,该系统能够从实际发现或遭遇钓鱼的用户发布的推文中,结构化和准确地提取钓鱼信息(例如URL和域名)。在三个月实时运行中,CrowdCanary从38,935份钓鱼报告中识别出35,432个钓鱼URL。我们确认其中31,960个(90.2%)钓鱼URL随后被反病毒引擎检测到,这表明CrowdCanary在威胁提取的准确性和数量上均优于现有系统。我们还利用提取的钓鱼URL分析了分享钓鱼威胁的用户,并将其分为两组——即专家和非专家。结果发现,CrowdCanary能够收集到非专家报告中特有的信息,例如推文中仅以公司品牌名称分享的信息、仅出现在推文图像中的钓鱼攻击相关信息,以及重定向前的着陆页面信息。