• DocumentCode
    1809600
  • Title

    Discovering phishing dropboxes using email metadata

  • Author

    Moore, Tyler ; Clayton, Richard

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Southern Methodist Univ., Dallas, TX, USA
  • fYear
    2012
  • fDate
    23-24 Oct. 2012
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    The criminals who operate phishing scams often deliver harvested credentials to email accounts under their control - but it is difficult, in the general case, to identify these so-called `dropboxes´. We devise three techniques to identify dropboxes and associated phishing websites by leveraging lists of known phishing websites and metadata maintained by email providers. We demonstrate the techniques´ effectiveness using data held by anti-phishing organizations and an email provider. To directly identify dropboxes, we posted fake but distinctive credentials into 170 PayPal phishing pages and inspected an email provider´s anti-spam metadata. This metadata recorded the presence of our credentials matching 28 of the phishing pages sending credentials to 17 distinct dropboxes at this particular email provider. We indirectly identified 24 additional dropboxes by searching for email subjects similar to previously-uncovered dropboxes. Based on these findings, we estimate an upper bound of 120 - 160 criminals ran phishing attacks against PayPal in July 2012, a smaller figure than might be expected from the 26 900 PayPal distinct phishing URLs they are known to have employed, spread across 13 018 different hostnames. Finally, in some cases we could extend our metadata processing by running an `intersection attack´. Whenever victims receive the same URLs as other victims, it is likely that the common URL is for a phishing page. Preliminary evidence suggests that the false positive rate for intersection attacks is low. Furthermore, it can be used to notify impersonated brands immediately after victims disclose their credentials and identify more phishing sites faster than traditional methods currently achieve.
  • Keywords
    Web sites; computer crime; meta data; unsolicited e-mail; PayPal phishing pages; antiphishing organizations; antispam metadata; credential matching; dropbox identification; email accounts; email metadata; email providers; intersection attack; phishing URL; phishing Web sites; phishing attack; phishing dropbox discovery; phishing scams; upper bound;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    eCrime Researchers Summit (eCrime), 2012
  • Conference_Location
    Las Croabas
  • ISSN
    2159-1237
  • Print_ISBN
    978-1-4673-2544-8
  • Type

    conf

  • DOI
    10.1109/eCrime.2012.6489515
  • Filename
    6489515