Skip to main content

2020 | OriginalPaper | Buchkapitel

Prevention of Phishing Attack in Internet-of-Things based Cyber-Physical Human System

verfasst von : Alekha Kumar Mishra, Asis Kumar Tripathy, Sowmya Saraswathi, Meenakshi Das

Erschienen in: High Performance Vision Intelligence

Verlag: Springer Singapore

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

In Internet-of-Things enabled Cyber-Physical Human System (CPHS), the controller control the destination systems. The challenger or hacker can perform a number of attacks on this network to threaten the identity and vulnerability of the system, by consuming the networked resources. One of the issue that possesses threat on identities and user credentials is the phishing. The mechanisms for phishing detection in IoT based CPHS should be light-weight and not much complicated in order to meet the CPHS requirement. In CPHS, the credentials can be compromised from the user by showing very similar electronic pages or messages, and encouraging user to provide their secured financial data. These issues need to be resolved in order to get the right output and get all the functionalities to work properly. CPHS has mainly two major components, the first one is controller and second one is destination system. Commands are sent from the sensor to the destination via sensor nodes on the network and the destination system communicates with the controller about what actions to perform or how to deal with the information that controller has sent.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat T.N. Jagatic, N.A. Johnson, M. Jakobsson, F. Menczer, Social phishing. Commun ACM 50(10), 94–100 (2007) T.N. Jagatic, N.A. Johnson, M. Jakobsson, F. Menczer, Social phishing. Commun ACM 50(10), 94–100 (2007)
2.
Zurück zum Zitat P. Kumaraguru, Y. Rhee, S. Sheng, S. Hasan, A. Acquisti, L.F. Cranor, J. Hong, Teaching Johnny not to fall for phish. ACM Trans. Internet Technol. (TOIT) 10(2), 7:1–7:31 (2010) P. Kumaraguru, Y. Rhee, S. Sheng, S. Hasan, A. Acquisti, L.F. Cranor, J. Hong, Teaching Johnny not to fall for phish. ACM Trans. Internet Technol. (TOIT) 10(2), 7:1–7:31 (2010)
3.
Zurück zum Zitat I. Khalil, S. Bagchi, N. Shroff, Analysis and evaluation of Secos, a protocol for energy efficient and secure communication in sensor networks. Ad Hoc Netw. 5(3), 360–391 (2007)CrossRef I. Khalil, S. Bagchi, N. Shroff, Analysis and evaluation of Secos, a protocol for energy efficient and secure communication in sensor networks. Ad Hoc Netw. 5(3), 360–391 (2007)CrossRef
4.
Zurück zum Zitat G. Varshney, M. Misra, P.K. Atrey, A survey and classification of web phishing detection schemes. Secur. Commun. Netw. 9(18), 6266–6284 (2016)CrossRef G. Varshney, M. Misra, P.K. Atrey, A survey and classification of web phishing detection schemes. Secur. Commun. Netw. 9(18), 6266–6284 (2016)CrossRef
5.
Zurück zum Zitat J. Hong, The state of phishing attacks. Commun. ACM 55(1), 74–81 (2012)CrossRef J. Hong, The state of phishing attacks. Commun. ACM 55(1), 74–81 (2012)CrossRef
6.
Zurück zum Zitat K.L. Chiew, K.S.C. Yong, C.L. Tan, A survey of phishing attacks: their types, vectors and technical approaches. Expert Syst. Appl. 106, 1–20 (2018)CrossRef K.L. Chiew, K.S.C. Yong, C.L. Tan, A survey of phishing attacks: their types, vectors and technical approaches. Expert Syst. Appl. 106, 1–20 (2018)CrossRef
7.
Zurück zum Zitat H. Huang, J. Tan, and L. Liu, Countermeasure techniques for deceptive phishing attack, in Proceedings of International Conference on New Trends in Information and Service Science, pp. 636–641 (2009) H. Huang, J. Tan, and L. Liu, Countermeasure techniques for deceptive phishing attack, in Proceedings of International Conference on New Trends in Information and Service Science, pp. 636–641 (2009)
8.
Zurück zum Zitat B. Parmar, Protecting against spear-phishing. Comput. Fraud. Secur. 2012(1), 8–11 (2012)CrossRef B. Parmar, Protecting against spear-phishing. Comput. Fraud. Secur. 2012(1), 8–11 (2012)CrossRef
9.
Zurück zum Zitat C. Karlof, U. Shankar, J.D. Tygar, D. Wagner, Dynamic pharming attacks and locked same-origin policies for web browsers, in Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 58–71 (2007) C. Karlof, U. Shankar, J.D. Tygar, D. Wagner, Dynamic pharming attacks and locked same-origin policies for web browsers, in Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 58–71 (2007)
10.
Zurück zum Zitat B.B. Gupta, N.A.G. Arachchilage, K.E. Psannis, Defending against phishing attacks: taxonomy of methods, current issues and future directions. Telecommun. Syst. 67(2), 247–267 (2018) B.B. Gupta, N.A.G. Arachchilage, K.E. Psannis, Defending against phishing attacks: taxonomy of methods, current issues and future directions. Telecommun. Syst. 67(2), 247–267 (2018)
11.
Zurück zum Zitat N. Chou, R. Ledesma, Y. Teraguchi, J.C. Mitchell, Client-side defense against web-based identity theft, in Proceedings of the Network and Distributed System Security Symposium, NDSS 2004, pp. 01–16 (2004) N. Chou, R. Ledesma, Y. Teraguchi, J.C. Mitchell, Client-side defense against web-based identity theft, in Proceedings of the Network and Distributed System Security Symposium, NDSS 2004, pp. 01–16 (2004)
12.
Zurück zum Zitat T. Raffetseder, E. Kirda, C. Kruegel, Building anti-phishing browser plug-ins: an experience report, in Proceedings of the 3rd International Workshop on Software Engineering for Secure Systems, pp. 1–6 (2007) T. Raffetseder, E. Kirda, C. Kruegel, Building anti-phishing browser plug-ins: an experience report, in Proceedings of the 3rd International Workshop on Software Engineering for Secure Systems, pp. 1–6 (2007)
13.
Zurück zum Zitat A. Stone, Natural-language processing for intrusion detection. Computer 40(12), 103–105 (2007)CrossRef A. Stone, Natural-language processing for intrusion detection. Computer 40(12), 103–105 (2007)CrossRef
14.
Zurück zum Zitat M. Sharifi, S.H. Siadati, A phishing sites blacklist generator, in 2008 IEEE/ACS International Conference on Computer Systems and Applications, pp. 840–843 (2008) M. Sharifi, S.H. Siadati, A phishing sites blacklist generator, in 2008 IEEE/ACS International Conference on Computer Systems and Applications, pp. 840–843 (2008)
15.
Zurück zum Zitat D.L. Cook, V.K. Gurbani, M. Daniluk, Phishwish: a simple and stateless phishing filter. Secur. Commun. Netw. 2(1), 29–43 (2008)CrossRef D.L. Cook, V.K. Gurbani, M. Daniluk, Phishwish: a simple and stateless phishing filter. Secur. Commun. Netw. 2(1), 29–43 (2008)CrossRef
16.
Zurück zum Zitat Y. Joshi, S. Saklikar, D. Das, S. Saha, PhishGuard: a browser plug-in for protection from phishing, in 2008 2nd International Conference on Internet Multimedia Services Architecture and Applications, pp. 1–6 (2008) Y. Joshi, S. Saklikar, D. Das, S. Saha, PhishGuard: a browser plug-in for protection from phishing, in 2008 2nd International Conference on Internet Multimedia Services Architecture and Applications, pp. 1–6 (2008)
17.
Zurück zum Zitat M. Hara, A. Yamada, Y. Miyake, Visual similarity-based phishing detection without victim site information, in IEEE Symposium on Computational Intelligence in Cyber Security, pp. 30–36 (2009) M. Hara, A. Yamada, Y. Miyake, Visual similarity-based phishing detection without victim site information, in IEEE Symposium on Computational Intelligence in Cyber Security, pp. 30–36 (2009)
18.
Zurück zum Zitat C. Yue, H. Wang. BogusBiter: a transparent protection against phishing attacks. ACM Trans. Internet Technol. 10(2), 6:1–6:31 (2010) C. Yue, H. Wang. BogusBiter: a transparent protection against phishing attacks. ACM Trans. Internet Technol. 10(2), 6:1–6:31 (2010)
19.
Zurück zum Zitat P. Prakash, M. Kumar, R.R. Kompella, M. Gupta, PhishNet: predictive blacklisting to detect phishing attacks, in Proceedings IEEE INFOCOM, pp. 1 – 5 (2010) P. Prakash, M. Kumar, R.R. Kompella, M. Gupta, PhishNet: predictive blacklisting to detect phishing attacks, in Proceedings IEEE INFOCOM, pp. 1 – 5 (2010)
20.
Zurück zum Zitat A. Bergholz, J. De Beer, S. Glahn, M.-F. Moens, G. Paaß, S. Strobel, New filtering approaches for phishing email. J. Comput. Secur. 18(1), 7–35 (2010)CrossRef A. Bergholz, J. De Beer, S. Glahn, M.-F. Moens, G. Paaß, S. Strobel, New filtering approaches for phishing email. J. Comput. Secur. 18(1), 7–35 (2010)CrossRef
21.
Zurück zum Zitat C. Whittaker, B. Ryner, M. Nazif, Large-scale automatic classification of phishing pages, in Proceedings of the Network and Distributed System Security Symposium, NDSS 2010, pp. 01–14 (2010) C. Whittaker, B. Ryner, M. Nazif, Large-scale automatic classification of phishing pages, in Proceedings of the Network and Distributed System Security Symposium, NDSS 2010, pp. 01–14 (2010)
22.
Zurück zum Zitat G. Liu, B. Qiu, L. Wenyin, Automatic detection of phishing target from phishing webpage, in 20th International Conference on Pattern Recognition, pp. 4153–4156 (2010) G. Liu, B. Qiu, L. Wenyin, Automatic detection of phishing target from phishing webpage, in 20th International Conference on Pattern Recognition, pp. 4153–4156 (2010)
23.
Zurück zum Zitat B. Wardman, T. Stallings, G. Warner, A. Skjellum, High-performance content-based phishing attack detection, in Proceedings of eCrime Researchers Summit, pp. 1–9 (2011) B. Wardman, T. Stallings, G. Warner, A. Skjellum, High-performance content-based phishing attack detection, in Proceedings of eCrime Researchers Summit, pp. 1–9 (2011)
24.
Zurück zum Zitat S. Afroz, R. Greenstadt, PhishZoo: detecting phishing websites by looking at them, in 2011 IEEE 5th International Conference on Semantic Computing, pp. 368–375 (2011) S. Afroz, R. Greenstadt, PhishZoo: detecting phishing websites by looking at them, in 2011 IEEE 5th International Conference on Semantic Computing, pp. 368–375 (2011)
25.
Zurück zum Zitat H. Kim, J.H. Huh, Detecting DNS-poisoning-based phishing attacks from their network performance characteristics. Electron. Lett. 47(11), 656–658 (2011)CrossRef H. Kim, J.H. Huh, Detecting DNS-poisoning-based phishing attacks from their network performance characteristics. Electron. Lett. 47(11), 656–658 (2011)CrossRef
26.
Zurück zum Zitat H. Zhang, G. Liu, T.W.S. Chow, W. Liu, Textual and visual content-based anti-phishing: a bayesian approach. IEEE Trans. Neural Netw. 22(10), 1532–1546 (2011)CrossRef H. Zhang, G. Liu, T.W.S. Chow, W. Liu, Textual and visual content-based anti-phishing: a bayesian approach. IEEE Trans. Neural Netw. 22(10), 1532–1546 (2011)CrossRef
27.
Zurück zum Zitat E.H. Chang, K.L. Chiew, S.N. Sze, W.K. Tiong, Phishing detection via identification of website identity, in 2013 International Conference on IT Convergence and Security (ICITCS), pp. 1–4 (2013) E.H. Chang, K.L. Chiew, S.N. Sze, W.K. Tiong, Phishing detection via identification of website identity, in 2013 International Conference on IT Convergence and Security (ICITCS), pp. 1–4 (2013)
28.
Zurück zum Zitat T.-C. Chen, T. Stepan, S. Dick, J. Miller, An anti-phishing system employing diffused information. ACM Trans. Inf. Syst. Secur. 16(4), 16:1–16:31 (2014) T.-C. Chen, T. Stepan, S. Dick, J. Miller, An anti-phishing system employing diffused information. ACM Trans. Inf. Syst. Secur. 16(4), 16:1–16:31 (2014)
29.
Zurück zum Zitat N.M. Shekokar, C. Shah, M. Mahajan, S. Rachh, An ideal approach for detection and prevention of phishing attacks. Procedia Comput. Sci. 49, 82–91 (2015); Proceedings of 4th International Conference on Advances in Computing, Communication and Control (ICAC3’15) N.M. Shekokar, C. Shah, M. Mahajan, S. Rachh, An ideal approach for detection and prevention of phishing attacks. Procedia Comput. Sci. 49, 82–91 (2015); Proceedings of 4th International Conference on Advances in Computing, Communication and Control (ICAC3’15)
30.
Zurück zum Zitat G. Ramesh, J. Gupta, P.G. Gamya, Identification of phishing webpages and its target domains by analyzing the feign relationship. J. Inf. Secur. Appl. 35, 75–84 (2017) G. Ramesh, J. Gupta, P.G. Gamya, Identification of phishing webpages and its target domains by analyzing the feign relationship. J. Inf. Secur. Appl. 35, 75–84 (2017)
31.
Zurück zum Zitat Y. Zhang, J.I. Hong, L.F. Cranor, Cantina: a content-based approach to detecting phishing web sites, in Proceedings of the 16th International Conference on World Wide Web, pp. 639–648 (2007) Y. Zhang, J.I. Hong, L.F. Cranor, Cantina: a content-based approach to detecting phishing web sites, in Proceedings of the 16th International Conference on World Wide Web, pp. 639–648 (2007)
32.
Zurück zum Zitat E. Medvet, E. Kirda, C. Kruegel, Visual-similarity-based phishing detection, in Proceedings of the 4th International Conference on Security and Privacy in Communication Netowrks, pp. 22:1–22:6 (2008) E. Medvet, E. Kirda, C. Kruegel, Visual-similarity-based phishing detection, in Proceedings of the 4th International Conference on Security and Privacy in Communication Netowrks, pp. 22:1–22:6 (2008)
33.
Zurück zum Zitat K.-T. Chen, J.-Y. Chen, C.-R. Huang, C.-S. Chen, Fighting phishing with discriminative keypoint features. IEEE Internet Comput. 13(3), 56–63 (2009)CrossRef K.-T. Chen, J.-Y. Chen, C.-R. Huang, C.-S. Chen, Fighting phishing with discriminative keypoint features. IEEE Internet Comput. 13(3), 56–63 (2009)CrossRef
34.
Zurück zum Zitat A. Blum, B. Wardman, T. Solorio, G. Warner, Lexical feature based phishing url detection using online learning, in Proceedings of the 3rd ACM Workshop on Artificial Intelligence and Security, pp 54–60 (2010) A. Blum, B. Wardman, T. Solorio, G. Warner, Lexical feature based phishing url detection using online learning, in Proceedings of the 3rd ACM Workshop on Artificial Intelligence and Security, pp 54–60 (2010)
35.
Zurück zum Zitat G. Xiang, J. Hong, C.P. Rose, L. Cranor. CANTINA+: a feature-rich machine learning framework for detecting phishing web sites. ACM Trans. Inf. Syst. Secur. (TISSEC) 14(2), 21:1–21:28 (2011) G. Xiang, J. Hong, C.P. Rose, L. Cranor. CANTINA+: a feature-rich machine learning framework for detecting phishing web sites. ACM Trans. Inf. Syst. Secur. (TISSEC) 14(2), 21:1–21:28 (2011)
36.
Zurück zum Zitat Y. Zhou, Y. Zhang, J. Xiao, Y. Wang, W. Lin, Visual similarity based anti-phishing with the combination of local and global features, in 2014 IEEE 13th International Conference on Trust, Security and Privacy in Computing and Communications, pp 189–196 (2014) Y. Zhou, Y. Zhang, J. Xiao, Y. Wang, W. Lin, Visual similarity based anti-phishing with the combination of local and global features, in 2014 IEEE 13th International Conference on Trust, Security and Privacy in Computing and Communications, pp 189–196 (2014)
37.
Zurück zum Zitat C.L. Tan, K.L. Chiew, K. Wong, S.N. Sze, PhishWHO: phishing webpage detection via identity keywords extraction and target domain name finder. Decis. Support Syst. 88, 18–27 (2016) C.L. Tan, K.L. Chiew, K. Wong, S.N. Sze, PhishWHO: phishing webpage detection via identity keywords extraction and target domain name finder. Decis. Support Syst. 88, 18–27 (2016)
Metadaten
Titel
Prevention of Phishing Attack in Internet-of-Things based Cyber-Physical Human System
verfasst von
Alekha Kumar Mishra
Asis Kumar Tripathy
Sowmya Saraswathi
Meenakshi Das
Copyright-Jahr
2020
Verlag
Springer Singapore
DOI
https://doi.org/10.1007/978-981-15-6844-2_2

Neuer Inhalt