Title
A quantitative approach to estimate a website security risk using whitelist
Abstract
Despite much research on defense against phishing attacks, incidents continue to occur where sensitive (e.g., personal or financial) information is stolen using social engineering and technical spoofing techniques. Most approaches use the notions of blacklists versus whitelists (WWLs), and it is difficult to quantify the degree of a website's vulnerability against phishing attacks. In this paper, we present a quantitative approach for evaluating the phishing possibility of a given website using the refined security risk elements for domain and web page. Design and implementation of the website risk assessment system for antiphishing are also included. It can detect suspicious websites containing phishing attack and abnormal behavior and generates a warning if website is judged untrustworthy. Copyright © 2012 John Wiley & Sons, Ltd.
Year
DOI
Venue
2012
10.1002/sec.420
Security and Communication Networks
Keywords
Field
DocType
suspicious web,abnormal behavior,refined security risk element,phishing attack,quantitative approach,website risk assessment system,website security risk,technical spoofing technique,john wiley,social engineering,phishing possibility,phishing,risk analysis,pharming
Internet privacy,Phishing,Web page,Spoofing attack,Computer security,Computer science,Pharming,Social engineering (security),Whitelist,Web application security,Spoofed URL
Journal
Volume
Issue
ISSN
5
10
1939-0114
Citations 
PageRank 
References 
0
0.34
26
Authors
4
Name
Order
Citations
PageRank
Young-Gab Kim119729.21
Minsoo Lee231531.33
Sang-Hyun Cho314321.38
Sungdeok Cha422019.73