Close This site uses cookies. If you continue to use the site you agree to this. For more details please see our cookies policy.

Search

Type your text, and hit enter to search:

Outsmarting phishing scams 

Phishing is a rampant form of cybercrime. Criminals impersonate trusted entities such as banks or employers to get victims to share sensitive information, click malicious links, or install harmful software. Less digital-savvy people are at particular risk, which not only widens the digital divide, but also erodes trust in essential digital institutions.

Phishing - 2 (2)
Image by tatoenjoy | Magnific

This is why researchers have been looking for ways to shut down phishing campaigns. However, they face severe challenges. For example, most existing approaches involve analysing individual, suspicious links on the web, or Uniform Resource Locators (URLs). While machine learning and deep learning approaches have helped realise increasingly sophisticated programmes that can assess content for veracity, cybercriminals can generally produce far more malicious links in the same time it takes to identify and shut down one site. Malicious content generation is also becoming cleverer; cloaking technologies can help fool scanners, leading to more malicious content making it in front of potential victims.

Now, researchers are looking for a paradigm shift. In recent work, a team led by Associate Professor Daiki Chiba from Tokyo Metropolitan University, Japan, adopted a new approach. Rather than trying to label single links as good or bad, they looked for signs of cloaking as a starting point for a whole, automated investigation to identify the whole phishing campaign associated with a malicious actor. 

Their system, PhishLumos, is not evaded by withheld content, but triggered instead. Once activated, it will look for clues in the ‘infrastructure’ of the URL, like which Internet Protocol (IP) numbers are involved, and which network connections are used. These help map out the whole campaign of URLs involved in the same phishing project, not simply as a big list of URLs, but a so-called Knowledge Base (KB) graph that describes how the campaign works.

Looking at 103 real phishing campaigns, PhishLumos was able to achieve detection eight days faster than experts on average. In real-world tests, given 600 seed URLs as starting points, the rules that it uncovered led to the discovery of over 190,000 new links, of which 92 per cent were later flagged as malicious. Importantly, it significantly outperformed so-called ‘content-centric’ approaches, which go through website content instead of infrastructure clues.

Online services are already an indispensable part of modern society, so bad actors can cause widespread, irreparable harm to society. Projects such as PhishLumos are an essential part of making sure that the benefits of new information technologies reach everyone in a safe and fair way.

DOI: 10.1109/ACCESS.2026.3696597

    Tweet       Post       Post
Oops! Not a subscriber?

This content is available to subscribers only. Click here to subscribe now.

If you already have a subscription, then login here.