PhishLive: a view of phishing and malware attacks from an edge router

  • Authors:
  • Lianjie Cao;Thibaut Probst;Ramana Kompella

  • Affiliations:
  • Purdue University, West Lafayette, Indiana;INSA de Toulouse, Toulouse, France;Purdue University, West Lafayette, Indiana

  • Venue:
  • PAM'13 Proceedings of the 14th international conference on Passive and Active Measurement
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Malicious website attacks including phishing, malware, and drive-by downloads have become a huge security threat to today's Internet. Various studies have been focused on approaches to prevent users from being attacked by malicious websites. However, there exist few studies that focus on the prevalence and temporal characteristics of such attack traffic. In this paper, we developed the PhishLive system to study the behavior of malicious website attacks on users and hosts of the campus network of a large University by monitoring the HTTP connections for malicious accesses. During our experiment of one month, we analyzed over 1 billion URLs. Our analysis reveals several interesting findings.