Phishing is a major problem on the Web. Despite the significant attention it has received over the years, there has been no
definitive solution. While the state-of-the-art solutions have reasonably good performance, they suffer from several drawbacks including
potential to compromise user privacy, difficulty of detecting phishing websites whose content change dynamically, and reliance on
features that are too dependent on the training data.
To address these limitations we present a new approach for detecting phishing webpages in real-time as they are visited by a browser.
It relies on modeling inherent phisher limitations stemming from the constraints they face while building a webpage. Consequently, the
implementation of our approach, Off-the-Hook, exhibits several notable properties including high accuracy, brand-independence and
good language-independence, speed of decision, resilience to dynamic phish and resilience to evolution in phishing techniques.
Off-the-Hook is implemented as a fully-client-side browser add-on, which preserves user privacy. In addition, Off-the-Hook identifies
the target website that a phishing webpage is attempting to mimic and includes this target in its warning. We evaluated Off-the-Hook in
two different user studies. Our results show that users prefer Off-the-Hook warnings to Firefox warnings.
فیشینگ یک مشکل عمده در وب است. علیرغم توجه قابل ملاحظه ای که در طول سال ها دریافت کرده است، هیچ اتفاقی نیفتاده است.
هنوز راه حل قطعی برای این مشکل بوجود نیامده در حالیکه راهکارهای بسیار زیادی در حال پیشرفت می باشند اما این راهکارها از چند مشکل عمده معمولا رنج می برند که می توان از جمله به :نا سازگاری با حریم خصوصی کاربر یکی از مشکلات فیشینگ در وب سایت های مختلف تحت وب می باشد.