Skip to main navigation Skip to search Skip to main content

PHONEY: Mimicking user response to detect phishing attacks

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

60 Scopus citations

Abstract

Phishing scams pose a serious threat to end-users and commercial institutions alike. Email continues to be the favorite vehicle to perpetrate such scams mainly due to its widespread use combined with the ability to easily spoof them. Several approaches, both generic and specialized, have been proposed to address this problem. However, phishing techniques, growing in ingenuity as well as sophistication, render these solutions weak. In this paper we propose a novel approach to detect phishing attacks using fake responses which mimic real users, essentially, reversing the role of the victim and the adversary. Our prototype implementation called PHONEY, sits between a user's mail transfer agent (MTA) and mail user agent (MUA) and processes each arriving email for phishing attacks. Using live email data collected over a period of eight months we demonstrate data that our approach is able to detect a wider range of phishing attacks than existing schemes. Also, the performance analysis study shows that the implementation overhead introduced by our tool is very negligible.

Original languageEnglish
Title of host publicationProceedings - WoWMoM 2006
Subtitle of host publication2006 International Symposium on a World of Wireless, Mobile and Multimedia Networks
Pages668-672
Number of pages5
DOIs
StatePublished - 2006
EventWoWMoM 2006: 2006 International Symposium on a World of Wireless, Mobile and Multimedia Networks - Buffalo-Niagara Falls, NY, United States
Duration: Jun 26 2006Jun 29 2006

Publication series

NameProceedings - WoWMoM 2006: 2006 International Symposium on a World of Wireless, Mobile and Multimedia Networks
Volume2006

Conference

ConferenceWoWMoM 2006: 2006 International Symposium on a World of Wireless, Mobile and Multimedia Networks
Country/TerritoryUnited States
CityBuffalo-Niagara Falls, NY
Period06/26/0606/29/06

Fingerprint

Dive into the research topics of 'PHONEY: Mimicking user response to detect phishing attacks'. Together they form a unique fingerprint.

Cite this