zerohour-phishing-detection / zpd-server

Code and test data for anti-phishing tool: A decision-support tool for experimentation on zero-hour phishing detection
Creative Commons Attribution 4.0 International
2 stars 0 forks source link

As seen in Usenix Filter by Google safe browsing and by website published date #26

Open ronalddenouden opened 3 months ago

ronalddenouden commented 3 months ago

Popular websites, non phising websites are often online for longer and can be checked with google safe browsing. See the paper for additional context besides:

"Phishing attackers have no incentive to publicly expose their links for long-term recognition, as they typically share them privately via email [49]. To evade detection by blacklist-based engines like Google Safe Browsing, these links may persist for a few days [48]. Hence, we argue that the condition "webpage w is popular" is sufficient but unnecessary to classify it as benign (i.e., non-phishing). Hence, the problem of validating benignity can be reduced to that of validating popularity, which is an easier problem to solve. We define the webpage w as popular if the following criteria are met:" see the usenixsecurity23-liu-ruofan.pdf