<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>A Middleware based Anti-Phishing Architecture</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>CCS Concepts</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>A.A Orunsolu Department of Computer Science Moshood Abiola Polytechnic Abeokuta</institution>
          ,
          <country country="NG">Nigeria</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>A.S Sodiya Department of Computer Science Federal University of Agriculture</institution>
          ,
          <addr-line>Abeokuta</addr-line>
          ,
          <country country="NG">Nigeria</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>A.T Akinwale Department of Computer Science Federal University of Agriculture</institution>
          ,
          <addr-line>Abeokuta</addr-line>
          ,
          <country country="NG">Nigeria</country>
        </aff>
      </contrib-group>
      <fpage>122</fpage>
      <lpage>128</lpage>
      <abstract>
        <p>Phishing attacks are becoming an everyday threat to the ever growing cyber community. Regrettably, most online users do not understand some of the simplest indicators of a typical phishing scam. In addition, the sophistication of some of the newest phishing defeat most of the current software-based against phishing attacks.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Attacks</kwd>
        <kwd>E-Commerce</kwd>
        <kwd>Middleware</kwd>
        <kwd>Phishing</kwd>
        <kwd>Internet</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. INTRODUCTION</title>
      <p>
        The prevalence of e-services in today’s digital world has opened a
door for various cyber-crimes that threatened the acceptability of
such services. Hackers have continuously managed a host of online
black markets which discourage stakeholders’ confidence in the
usability of internet services [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. This range of criminal
enterprises includes spam-advertised commerce, botnet attacks,
and a vector for propagating malware [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Among all the
cybercrimes targeting e-services, phishing attacks have become a
significant security threat which causes tremendously losses every
day to both experienced and unwary internet users [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. This is
mostly due to the unhealthy disclosure of user’s credentials to a
phishing-related sites, chats, SMS or e-mail. Thus, these crimes
have subjected the popular advantages of Internet to debate as
businesses, government, individuals and financial institutions
recorded millions of dollars in losses and espionage.
      </p>
      <p>
        Phishing is e-communication criminal act which uses social
engineering and technical subterfuge to exploit unwary internet
users and acquire their confidential data such as credit card
number, PIN, password, answer to security questions etc. Social
engineering-based phishing techniques use spoofed emails, chat or
SMS to lead internet users to fake agents, websites etc. On the
other hand, technical subterfuge-based phishing scheme plant
crime ware unto computers to steal sensitive data. Recently,
phishers develop “ransomware” which executes a cryptovirology
attack that adversely affects computing resources and demands a
ransom payment to restore the resources to original state.
According to an online report by CSO, 93% of phishing emails are
now “ransomware”. The report observed that most victims tend to
pay quickly because of the sensitive nature of their resources [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
Basically, a typical phishing attack begins with unauthenticated
message crafted by phishers. These messages arrived at the client
or user’s machine in the form of email, e-advert, SMS, websites
etc. with brand logos and call center number of a known company.
One of the core features of these messages is their deceptive view
which may not be easily identified even to an experienced
ITexpert [
        <xref ref-type="bibr" rid="ref5 ref8">5, 8</xref>
        ]. The user falls for a phish by actively following the
instruction in the message through performing a click action or
download action. In the end, the user’s actions result to the
execution of phishers’ payload. A payload is the functional part of
a phisher’s code where their malicious intention is achieved.
Figure 1 presents the life cycle of a phishing attack.
      </p>
      <p>
        Ravaged by unhealthy reality of phishing attacks, researchers
proposed a number of countermeasures ranging from
usereducation to software enhancements. In spite of the existence of
various anti-phishing measures, the frequency of phishing
incidences continues to increase [
        <xref ref-type="bibr" rid="ref14 ref29">14, 29</xref>
        ]. For instance, RSA’s
online fraud report showed estimated losses of over $4.6 billion by
global organizations in 2015. In a similar vein, the Central Bank of
Nigeria White paper estimated that about $250 million was lost to
cybercrime in 2013 [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>To this end, we report the survey of anti-phishing researches and
examine their weaknesses. After survey of relevant extant
literature, we provide a brief discussion on a new approach that
will effectively mitigate the weakness of the current approaches.
This is a very important milestone in harnessing diverse
antiphishing defense system in one study to provide the basis for
evaluating the proposed paradigm-shift approach.</p>
      <p>The rest of the paper is organized as follows: Section 2 presents
related works on why phishing works. The overview of the current
anti-phishing defense architecture is examined in Section 3. In
Section 4, we present the proposed paradigm-shift architecture to
address current challenges. Section 5 presents our conclusions.</p>
    </sec>
    <sec id="sec-2">
      <title>2. WHY PHISHING WORKS?</title>
      <p>
        A number of studies have examined the reasons that people fall for
phishing attacks. For instance, Dhamija et al. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] identified lack of
computer system knowledge, lack of knowledge of security and
security indicators, visual deception and bounded attention. The
authors further showed that a large number of people cannot
differentiate between legitimate and phishing web sites, even when
they are made aware that their ability to identify phishing attacks
are being tested. In another related work, Down et al. [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]
conducted a research in which 20 non-expert computer users
revealed their strategies and understanding when faced with
possible suspicious e-mails.
      </p>
      <p>Phishing scams begin
1. Unauthenticated message arrives</p>
      <p>on unwary use’s machine
2. The message bears a deceptive</p>
      <p>view
3. User interact with the message by
performing some actions requested
by the message e.g. click, update etc
No</p>
      <p>Has user performed the
requested action?</p>
      <p>Yes
4. Phisher’s Payload
No payload execution</p>
      <p>
        End of campaign
The investigation showed that participants used basic, often
incorrect heuristics in deciding how to respond to email messages.
In another development, Sheng et al [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ] and Jakobsson et al. [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]
provided useful insights on why phishing works using
demographic data. While Sheng et al [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ] revealed that women are
more vulnerable than men due to their less exposure to technical
knowledge, Jakobsson et al [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] revealed users’ sensitivity to
variety of common trust indicators such as logos, padlock icons
etc. when navigating web pages. Jagatic et al. [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] researched into
a more sophisticated spear-phishing attacks in which the attackers
use specific knowledge of individuals and their organizations to
conduct attack. Their investigation showed that people were 4.5
times more likely to fall for phish sent from an existing contact
over standard phishing attacks. This is why social networking sites
like Facebook are now more patronized by phishers.
      </p>
      <p>
        Appealing to people’s sense of greed is an ancient technique now
adapted to the digital world especially in phishing scams [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. This
kind of phishing scam may look like online survey in which
unsuspicious users are promised some financial returns for
participating in the survey exercise. In a similar vein, phishers
might pose as relief agency asking for help with recent natural
disasters to appeal to people’s sense of emotion [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. Most
unsuspecting users may not suspect anything negative even when
asked to provide their financial details because of some gory
pictures that usually accompanied such campaigns.
      </p>
      <p>
        In a more recent study, Mohammed et al. conducted user study
with the use of eye tracker to obtain objective quantitative data on
user judgment of phishing sites. Their results indicated that users
detected 53% of phishing sites even when primed to identify them
with little attention on security indicators [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ].
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. THE CURRENT COUNTERMEASURES</title>
      <p>In this section, we considered the state of current countermeasures
against phishing attack from software enhancement perspective.
Software enhancement techniques are computer programs that are
designed to defeat or mitigate phishing attacks. These software
approaches use techniques such as list-based, machine learning,
visual similarity and multi-channel authentication algorithms. They
are either deployed on the client side or server side.</p>
    </sec>
    <sec id="sec-4">
      <title>3.1 Client-side Anti-phishing approaches</title>
      <p>
        PhishNet [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ] proposed an active blacklist approach in which new
malicious URLs can be effectively predicted from the existing
blacklist entries. This is achieved by processing blacklisted URLs
and producing multiple variations of the same URL using IP
address equivalence, query string substitution, brand name
equivalence, directory structure similarity and top level domain
replacement. In this way, multiple variations of the same URL
called children are obtained. In order to filter non-existent children
URLs, the system performed DNS query, TCP connect, HTTP
header response and content similarity. The approach achieved
remarkable results during real-time blacklist feeds against new
malicious URLs. However, the problem of false positives still
exists.
      </p>
      <p>
        PhishZoo [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] built profiles of trusted websites based on fuzzy
hashing techniques in a whitelisted based approach. The approach
also used blacklisting and heuristics approaches to warn users
about malicious sites. This approach compared the stored profile of
authentic sites with the content of sites under investigation. The
approach achieved significant accuracy rate of about 96% with the
possibility of defeating zero-day attack. However, there is lack of
generalization to new phishing due to human interventions.
Cao et al [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] developed an Automated Individual White-List
(AIWL) in which the record of well-known benign sites visited by
users is kept. In this way, AIWL maintains a record of every URL
along with its Login User Interface information where the user
input his or her details to prevent unhealthy disclosure of
confidential information to malicious sites. The LUI information
maintains by AIWL for any suspicious website include the URL,
the Input Area and the IPs. The URL refers to the Unified
Resource Locator of the website. The input area includes the form
username path and password path. The IPs is a list of legitimate IP
addresses mapping to a URL. This method is very effective against
pharming and dynamic phishing attacks. However, the problem of
new login can result in false alert
In the work of Downs et al [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], a behavior-based phishing
detection system (UBPD) which monitor submission of user
credentials by building binding relationship between users and web
pages was proposed. This is done by constructing a personal
whitelist for the user by adding web sites the user has visited more
than three times. UBPD consists of three components namely the
user profile, the monitor and the detection engine. The user profile
contains data to describe the user’s binding relationships and the
user’s personal whitelist. The monitor collects the data the user
intends to submit and the identity of the destination websites. The
detection engine uses the data provided by the monitor to detect
phishing websites and update the user profile if necessary. The
approach can be effectively applied to static authentication
credentials such as user name, password, security questions etc.
However, zero day attack is possible since prediction is only
applied to websites that user once visited.
      </p>
      <p>
        Gowtham et al [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] presented a dynamic defense approach in which
direct and indirect links in associated with a malicious page is
generated. In this way, the target domain set is constructed as input
into Target Identification algorithm to recognize a phishing page.
Using DNS lookup and IP address resolution, the suspicious page
can be predicted without the use of machine learning algorithms or
existing restriction lists. The accuracy rate of this approach was
99.62%. However, the prediction of this approach is largely
dependent on the TF-IDF algorithms, search engine speed and
DNS lookup. The unavailability of any of these, defeat the efficacy
of this approach.
      </p>
      <p>
        A model to test the trustworthiness of suspected phishing page was
developed in [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ] by checking if the response of websites matches
with the known behavior of phishing or legitimate sites. The model
used the notion of Finite State Machine to capture the submission
of forms with random inputs and then their corresponding
responses to describe the website’s behavior. The experimental
results showed zero false negative and positive rates. The ability to
detect advanced XSS-based attacks is another plus for this method.
However, the approach cannot handle phishing attacks where
images are employed.
      </p>
      <p>
        PhishAri [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] detects phishing on Twitter in real-time. The approach
uses Twitter specific features along with URL features to detect
whether a tweet posted with a URL is phishing or not. The features
used in this approach are classified into URL based, Tweet-based,
WHOIS-based and Network-based. The approach is implemented
as a Chrome browser extension which makes a call to a developed
API (called RESTful API) and accordingly shows an indicator next
to each tweet indicating whether the tweet is phishing or not.
Experimental result shows that the system achieves 92.52%
accuracy. The system detection speed can be improved with
presence of external database repositories. However, XSS attack is
still possible
In another work, Islam et al [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] proposed a multi-stage
methodology that employed natural language processing and
machine learning algorithm to detect phishing attack and discover
the organization that the attackers impersonated during phishing
attacks. The approach first discovered named entities and hidden
topics in a suspected message using Conditional Random Field and
Latent Dirichlet Allocation after parsing the message with the
Multipart Internet Mail Extension Parser and HTML parser. In the
next stage, utilizing topics and named entities as features, each
message was classified as phishing or non-phishing using
AdaBoost. In the final stage, the approach discovered the
impersonated organization using CRF. The approach ensured
automatic discovery of an impersonated entity, which help the
legitimate organization to take necessary action against the
offending site. The problem of scalability, false positives and the
requirement of an efficient parser still exist.
      </p>
      <p>
        The work of Maurer et al [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] focused on URL similarity for
detecting phishing pages by extracting and verifying different
terms of a URL using search engine recommendation. The authors
developed algorithms to detect possible search terms that were
worth checking using basename, subdomains, pathdomain and
brand name. Top Level Domain was used to extract the base
domain that was used with the search engine. The approach was
evaluated with a large set of 8730 URLs from online phishing
website database. The approach is effective against software
toolkits that launch a large number of phishing pages using
different URLs. However, high false positive rates affect the
efficiency of this approach. In addition, significant performance
issues like high overhead resulted as the system relies on
consecutively querying search engines to identify legitimate
domain.
      </p>
      <p>
        An offensive approach in which a large number of bogus
credentials are transparently fed into a suspected phishing page
was proposed in [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ]. In this way, the victim’s real credential is
concealed among bogus credentials thereby increasing the
overhead on phishers’ side in discerning the real credentials.
BogusBiter consists of four main modules: information extraction,
bogus credential generation, request submission and response
process. The information extraction module extracts the username
and password pair and its corresponding form element on a login
page. The bogus credential generation module generates bogus
credential based on an original credentials. The request submission
is responsible for spawing and submitting multiple HTTP requests.
The response process module determines the legitimacy of a
website based on its response to HTTP requests. The approach is
not bound to any specific phishing detection scheme and can be
incrementally deployed over the internet. However, this approach
can result in increased bandwidth overhead and it can be blocked
by phisher since the bogus credentials is being submitted by a
dedicated IP address.
      </p>
    </sec>
    <sec id="sec-5">
      <title>3.2 Server-side Anti-phishing Approaches</title>
      <p>
        The deployment of server-side anti-phishing defense system is not
very popular as client side solutions. One of such server-side based
solution is a practical authentication service in which the need for
preset user password is eliminated during information flow
between the client and the server [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. This is achieved through the
use of one-time passwords delivered on demand via a reliable
secondary communication channel. On the receipt of the OTP, the
user can login before the password expires. The proposed approach
involves two processes namely a registration process and a login
process with four participating entities: websites, instant messaging
service provider, users and phishers. In the registration process, a
user choose a unique account name, select a login password, fill in
all the required information fields, complete an additional IM
account registration and provide at least one type of personal
contact information. In the login process, the registered user can
log in with the OTP assigned by the website. The approach does
not suffer from client side vulnerabilities and cost of deployment is
low which increases the practicability of this method. The
approach cannot detected XSS attacks and phishing sites hosted on
compromised domains
In another approach, Chen et al [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] proposed an image based
antiphishing strategy that measure suspicious pages’ similarity to
actual sites based on discriminative key point features in web
pages is proposed. The approach defined three aspects of visual
similarity consisting of block-level similarity, layout similarity and
overall style similarity to compare pages during detection process.
Their invariant content descriptor, which uses the contrast context
histogram, computes the similarity degree between suspicious and
authentic pages. The proposed method takes a snapshot of a
suspected page and treats it as an image throughout the detection
process. It uses CCH to capture invariant information around
discriminative key points on the suspect page and then match the
descriptors with those of authentic pages that are often targeted by
phishers. However, the approach cannot detect phishing pages in
which phisher use images to mimic their target.
      </p>
      <p>
        The concept of dynamic security skins that allow humans to
distinguish one computer from another was proposed in [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ].
Dynamic security skins allow a remote web server to prove its
identity in a way that is easy for human user to verify and difficult
for attackers to spoof. This approach assigns each user a random
personalized photographic image that will always appear in the
password window. However, the ability of user to recall this image
is a subject of debate. In addition, it is difficult to convince web
master to apply these rules in web page creation.
      </p>
    </sec>
    <sec id="sec-6">
      <title>3.3 Summary of problems with the existing countermeasures</title>
      <p>
        In this subsection, we itemized the summary of the problems with
the existing anti-phishing system.
a. The inability of most existing anti-phishing countermeasures
to efficiently detect newer phishing scams i.e. possibility of
zero-day attacks which a type of attack mounted using hosts
that are not blacklisted or using techniques that evade known
approaches to phishing detection [
        <xref ref-type="bibr" rid="ref20 ref25">25, 20</xref>
        ]
b. Most of the existing countermeasures consider small set of
heuristics features in their approach and most browsers’
plugins anti-phishing solutions are susceptible to java
vulnerabilities [
        <xref ref-type="bibr" rid="ref25 ref27">25, 27</xref>
        ]
c. Although there has been substantial performance
improvement in detecting phishing, the foremost drawback of
methods currently in use, in particular for classification based
methods using statistical learning algorithms, continue to be
the false positive problem [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]
d. High computational overhead of most classification-based
anti-phishing countermeasures [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]
e. Lack of consensus and problems of coverage of most blacklist
techniques. In addition, the blacklist method cannot adapt the
filter to identify emerging rule changes in the intruders’
attacks [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ]
f. Intensive configuration and lack of users’ proper attention
with most client-side solutions [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]
g. Absence of holistic countermeasures that detect, prevent and
disrupt phishing scams. Most existing anti-phishing system
either focuses on phishing email or phishing website detection
[
        <xref ref-type="bibr" rid="ref13 ref19 ref6 ref7">6,7,13,19</xref>
        ]
      </p>
    </sec>
    <sec id="sec-7">
      <title>4. THE PROPOSED APPROACH</title>
      <p>
        The phishing problem has been and still is very important, and the
current detection and warning approach taken to address the
problem is not enough. Motivated by this challenge, we proposed a
paradigm-shift based architecture (Fig.3) based on middleware
technology. The middleware technology is one of the viable
alternatives to the challenges of client/server anti-phishing
techniques. The primary advantage of MT is that it leverages the
benefits of software as a service model. That is, software solution
or design remains external to their system and is accessible and
executable by a large numbers of individuals. The approach has
potentially great benefits to anti-phishing design: MT is able to
always keep the system up to date (fully maintained) as
administration is under the control of service provider, ensure the
anti-phishing service remains efficient (by automatically adding
new filter rules as required), interacts with a large volume of data
traffic which can be collated and analyzed for improved security
coverage in the fight against phishing, provide a suitable basis for
anomaly detection technology and the transparency it offers to
both the client and server. Nevertheless, the MT technology raises
the issue of scalability especially in a user intensive environment
like internet; but with the emergence of cloud computing
infrastructure this challenge can be easily leveraged [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ].
In this paradigm-shift approach, we shall employ Map Reduce
algorithm to aggregate web streams into different jobs as suggested
[
        <xref ref-type="bibr" rid="ref27">27</xref>
        ]. Map Reduce is a programming model and software
framework intended to facilitate and simplify the processing of
vast amount of data in parallel on large clusters. The aggregation
of tasks results into non-computational and computational classes.
In the non-computational class (PhishDetect C1), phishing
detection is done using list-based approach to reduce the
unnecessary computation within the system. If a phishing attack
cannot be detected by non-computational class, the computational
class is invoked to complete the detection process. In this case, the
extracted features from the suspected sites are compared with
trained feature vectors from a hybrid classifier (NB-SVM). The
proposed system will be implemented and evaluated using datasets
from research sources such as PhishTank, APWG etc. The
overview of the algorithm for the proposed scheme is presented in
Figure 3
      </p>
      <p>Get Web Document (webpages, email message, e-chat)</p>
      <p>Sort web document using Map-Reduce algorithms</p>
      <p>Generate the Mapper and the Reducer Function</p>
      <p>For each Mapper and Reducer Function, invoke
noncomputational Class</p>
      <p>If detection is accurately performed, the exit
Else send uncompleted task to computational Class</p>
      <p>Trained NB-SVM classifier on feature class on the
uncompleted task</p>
      <p>Classify the task and exit</p>
      <p>Figure 2. Pseudo code of the proposed scheme
Stage 1: The first stage of the architecture is where client
transactions are captured before being forwarded to the phishing
detection manager (PDM). When a user opens a page in the web
browser, the extension module accesses the DOM tree of the
downloaded page from web browser’s IFrame. Document Object
Model, is a World Wide Web consortium standard, that allows
programmers and scripts to dynamically access and update the
content, structure and style of documents. After the construction of
DOM, the transaction is also parsed to extract any hyperlinks
present in the body of the transaction or a webpage
At the same time, the transaction is also tokenizes in an attempt to
identify the named entities such as organization and hidden topics
that the phishers is trying to deceive the unsuspecting users.
Named entities are proper names that are names of people,
organization, location etc. in the body of a document. The robust
Conditional Random Field (CRF) which is an information retrieval
task that seeks to locate and classify elements in text documents as
one of these proper names is employed. The second task of the
tokenizer is to discover the hidden topics in a transaction which is
achieved by employing the Latent Dirichlet Allocation. LDA is
sensitive to changes in feature usage which make it good at
handling synonym. It is also robust to polysemy, features with
different meaning in different context. In addition, it can discover
threatening theme in a message and intentionally misspelled
features and conjoined features. The most powerful feature of LDA
is its ability to discover multiple topics from a single document.
Stage 1
Stage 2
Stage 3
Client/User Interface</p>
      <sec id="sec-7-1">
        <title>1R. eRterieqvueedst</title>
        <p>4. Response</p>
      </sec>
      <sec id="sec-7-2">
        <title>TraCnsoamcptioonneFnettch</title>
        <p>Non-ML UNITS</p>
        <p>ML UNIT</p>
        <p>Transaction
Response
Component
Transaction
Classification</p>
        <p>Component
Stage 2: This contains the core component of the proposed
technique that detect the phishing label of a transaction. The
phishing detection manager provides the link between the client
interface and the Secured Server Side Transaction (Stage 3). The
Orchestration Engine (OE) is responsible for managing
communication between the Machine Learning Detection units and
Non-Machine Learning Detection units. In this way, exception
management, transaction management, resource management and
components management are easily coordinated. The Phishing
Detection Manager offers methods for all the basic tasks associated
with the construction and interaction of the phishing detection
process. The core components of the phishing detection manager
are:
a. Transaction Fetch Component (TFC)
b. Transaction Preliminary Filter Component (TPFC)
c. Transaction Classification Component (TCC)
d. Transaction Response Component (TRC)
These four components are integrated into a Middleware system as
anti-phishing scheme using service model architecture. That is, the
anti-phishing scheme remains external to their system (i.e. the
server and client). In addition, the system is accessible and
executable by a large number of client machines irrespective of the
browser type.</p>
        <sec id="sec-7-2-1">
          <title>Transaction Fetch Component (TFC)</title>
          <p>
            The Transaction Fetch Component represents the entry point of
web requests into the Anti-Phishing System where billions of user
transactions are aggregated after the DOM construction and
tokenization for onward generation of phishing label with a cost
efficient response. The task of aggregation is made
computationally less expensive with the employment of Map
Reduce framework. This is consistent with the suggestion of [
            <xref ref-type="bibr" rid="ref27">27</xref>
            ].
Map Reduce is a programming model and software framework
intended to facilitate and simplify the processing of vast amounts
of data in parallel on large clusters such as Internet Web Streams
(IWS). The Map Reduce framework consists of a single master
JobTracker and one slave Task Tracker per cluster-node. The
master is responsible for scheduling the jobs' component tasks on
the slaves, monitoring them and re-executing the failed tasks. The
slaves execute the tasks as directed by the master. The core idea
behind Map Reduce is mapping your data set into a collection of
&lt;key, value&gt; pairs, and then reducing overall pairs with the same
key. However, it can be more efficient to sort data once during
insertion than sort them for each Map Reduce query. In the light of
this, an insertion sorting technique is adopted to increase the
efficiency of Map Reduce capability of TFC
          </p>
        </sec>
        <sec id="sec-7-2-2">
          <title>Transaction Preliminary Filter Component (TPFC)</title>
          <p>The output of Map Reduce algorithms provides the input into the
Transaction Preliminary Filter Components which involves the
following tasks:
1. Preliminary Transaction Filtering Module (PTFM) which
determine phishiness of a transaction without learning algorithms
using Anti-Phishing Dictionary with Customized Source Code
Scanner, Anti-Phishing Authentication System with ability to
detect abnormally in the login form and Phishing Toolkit Analyzer
using Phishing Toolkit Corpus. The rationale for the introduction
of this module is to reduce the system computation and enhances
efficient memory usage in a time-critical scenario like web scape.
This module is especially suited for preapproved sites and sites
with known popularity.
2. Feature Selection Module (FSM) which determines efficient
feature for classification in a Feature Generator Process using
efficient feature selection approach. The main attraction of this
module is to select most informative Comprehensive Anti-Phishing
Feature for efficient classification. FSM takes advantage of the
factors embedded within or surrounding a message (called
heuristic cues) such as its source, format, length, and subject, to
quickly make a validity assessment.
3.Cached Internet Resource Module which provides for faster
lookup and speed up the phishing label of a transaction using data
from WHOIS properties, Phish Tank, Crawling Instances etc. This
is to reduce superfluous computation on already labeled suspicious
webpage or transaction.</p>
        </sec>
        <sec id="sec-7-2-3">
          <title>Transaction Classification Component</title>
          <p>Given an identity and a set of features, the task of determining the
genuineness of a transaction is executed by a classification
algorithm. A classification algorithm automatically learns how to
make accurate predictions based on past or trained observations.
The Transaction Classification Component of HAPS uses a hybrid
classifier approach to provide an efficient status of a transaction.
Naïve Bayes and Support Vector Machine are combined as
hierarchical hybrid system model (NB-SVM) to maximize
detection accuracy and minimize computational complexity. The
NB is a relatively accurate classifier especially for large
dimensional dataset like web streams. However, capacity control
and generalization remains an issue. The main problem associated
with using SVM as classifier is the computational overhead needed
to transform text data into numerical data which is sometimes
termed as “vectorization”. Generally in PDM, the features of a web
transaction are directly vectorized by transforming the text
documents into numerical format using SVM. Thus, NB is used as
a pre-processor for selected features in the front end of the SVM to
vectorize corpus before the actual training and classification are
carried out. The motivations for the adoption of this hybrid
classifier approach are:
i. Improve the generalization of the overall system
ii. Maintain a comparatively feasible training time and
categorization time
iii. Overcome the limitations of list-based methods (e.g.
blacklist approach) by dynamically updating the training
patterns whenever there is new pattern during classification
iv. Ignore serious deficiencies in underlying algorithms of both
classifiers
v. Produces a simple computationally effective and highly
accurate classifier</p>
        </sec>
        <sec id="sec-7-2-4">
          <title>Transaction Response Component</title>
          <p>The Transaction Response Component provides a cost efficient
response to a classified transaction based on the severity of attack
as computed by the Threat Identification Module. The Transaction
Identification Module measures and identifies the threat severity
associated with a classified transaction. With classified
transactions, a TIM is proposed to proactively predict the level of
seriousness of the attack. This is necessary in advancing the notion
of HAPS to a high level especially for accessing the severity of
phishing campaign. Consider the TIM algorithm that assign a
threat score, 0 ≤t_i ≤1, to the ith transaction upon the occurrence
of the jth classification by PDM. The threat scores may
qualitatively identify the threat level upon classification as
compromised if t_i=1, threatened if 0&lt;t_i&lt;1, and unthreatened if
t_i=0.</p>
          <p>Stage 3: The third stage of the architecture ensures that only safe
transaction are forward or return to client for the completion of the
initiated task after necessary anti-phishing computation have been
performed. The orchestration engine of the PDM also makes web
calls into this stage when there is need for external sources of data
in validating a transaction under investigation. All transactions are
directed to benign server while malicious servers are bypassed.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>5. CONCLUSIONS AND FUTURE WORK</title>
      <p>As the rapid explosion of e-commerce witnessed unprecedented
adoption by online communities, phishing activities continue to
wreak havoc on unsuspecting users who access the e-commerce
services. In the process, both users and the service providers have
suffered millions of dollars in losses compare to any form of
cybercrime. Therefore, phishing has become a plague that
threatens stakeholders’ confidence in the security of online product
and services. Considerable researches have been done towards
protecting users from phishing attacks. Despite the efforts by the
research community, the industry, and law enforcement to develop
solutions to tackle the problem, phishing has shown no sign of
abating (Basnet et al. 2012) as each of these existing techniques
suffers from such major challenges. In this paper, we provide
survey of relevant literature from client/server-side perspective
anti-phishing defense systems. We illustrated some open problems
with the current counter strategy and make a case for a
paradigmshift defense system for a middleware-based approach. The
middleware-based approach overcomes some inherent challenges
of client and server-side approach through provision of enhanced
security, ease of configuration, optimization of load-balancing,
management of connections etc. In addition, we present a working
architecture of the proposed method. Future works will consider
the implementation of the proposed architecture on real-time
phishing data corpus as well as benign data corpus.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Afroz</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Greenstadt</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>PhishZoo detecting phishing websites by looking at them</article-title>
          .
          <source>In Proceedings of IEEE fifth international conference on semantic computing</source>
          (pp.
          <fpage>368</fpage>
          -
          <lpage>375</lpage>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Aggarwaly</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rajadesingan</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kumaraguru</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>PhishAri: Automatic realtime phishing detection on twitter</article-title>
          .
          <source>In Seventh IEEE APWG eCrime researchers summit (eCRS)</source>
          .
          <source>Las Croabas</source>
          , Puerto Rico,
          <fpage>22</fpage>
          -
          <lpage>25</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <source>[3] CSO Online report on phishing activities. Accessed</source>
          <year>2016</year>
          (
          <article-title>www</article-title>
          .csoonline.com/articles)
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Cao</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Han</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Le</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          <year>2008</year>
          .
          <article-title>Anti-phishing based on automated individual white-list</article-title>
          .
          <source>Proceedings of the 4th ACM Workshop on Digital Identity Management</source>
          , Alexandria, USA.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Dhamija</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tygar</surname>
            ,
            <given-names>J.D.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Hearst</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <year>2006</year>
          .
          <article-title>Why phishing works</article-title>
          .
          <source>Proc. of the IGCHI Conference on Human Factors in Computing Systems</source>
          , ACM Press, pp.
          <fpage>581</fpage>
          -
          <lpage>90</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Downs</surname>
            ,
            <given-names>J.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>M.B. Holbrook</surname>
            , and
            <given-names>L.F.</given-names>
          </string-name>
          <string-name>
            <surname>Cranor</surname>
          </string-name>
          (
          <year>2006</year>
          ).
          <article-title>Decision strategies and susceptibility to phishing</article-title>
          .
          <source>In Proceedings of the Second Symposium on Usable Privacy and Security (SOUPS</source>
          <year>2006</year>
          ). pp.
          <fpage>79</fpage>
          -
          <lpage>90</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Huang</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          (
          <year>2009</year>
          ), “
          <article-title>Fighting phishing with discriminative keypoint features”</article-title>
          ,
          <source>IEEE Internet Computing</source>
          , Vol.
          <volume>13</volume>
          No.
          <issue>3</issue>
          , pp.
          <fpage>56</fpage>
          -
          <lpage>63</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Gowtham</surname>
            <given-names>R</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Krishnamurthi</surname>
            <given-names>I.</given-names>
          </string-name>
          <year>2014</year>
          .
          <article-title>An efficacious method for detecting phishing webpages through target domain identification</article-title>
          .
          <source>Journal of Decision Support Systems</source>
          . Elsevier Press
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Han</surname>
            <given-names>W</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cao</surname>
            <given-names>Y</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bertino</surname>
            <given-names>E</given-names>
          </string-name>
          and
          <string-name>
            <surname>Yong</surname>
            <given-names>J.</given-names>
          </string-name>
          <year>2012</year>
          .
          <article-title>Using automated individual white-list to protect web digital identities</article-title>
          .
          <source>Expert Systems with Applications.</source>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Hong</surname>
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>The state of phishing attacks. Contributed Articles in the Communication of the ACM</article-title>
          . Vol
          <volume>55</volume>
          No 1
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Jagatic</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Johnson</surname>
          </string-name>
          , N.,
          <string-name>
            <surname>Jakobsson</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Menczer</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          (
          <year>2007</year>
          ).
          <article-title>Social phishing</article-title>
          .
          <source>Communications of the ACM</source>
          , Vol.
          <volume>50</volume>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Jakobsson</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Myers</surname>
            <given-names>S. A.</given-names>
          </string-name>
          (
          <year>2007</year>
          ).
          <article-title>Phishing and countermeasures: Understanding the increasing problem of identity theft</article-title>
          . Introduction to Phishing (Eds.), (pp.
          <fpage>1</fpage>
          -
          <lpage>2</lpage>
          ). New York: John Wiley &amp; Sons, Inc.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Islam</surname>
            <given-names>R</given-names>
          </string-name>
          and
          <string-name>
            <surname>Abawajy</surname>
            <given-names>J.</given-names>
          </string-name>
          <year>2013</year>
          .
          <article-title>Multi-tier phishing detection and filtering approach</article-title>
          .
          <source>Journal of Network and Computer Applications.</source>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Kathryn</surname>
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Agata</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Malcolm</surname>
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Marcus</surname>
            <given-names>B</given-names>
          </string-name>
          and
          <string-name>
            <surname>Cate</surname>
            <given-names>J.</given-names>
          </string-name>
          <year>2015</year>
          .
          <article-title>The design of phishing studies: Challenges for researchers</article-title>
          .
          <source>Journal of Computers and Security.</source>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Longe</surname>
            <given-names>T.</given-names>
          </string-name>
          <year>2014</year>
          .
          <article-title>Ensuring Information Security Assurance through Policy Framework</article-title>
          .
          <source>Proc. of First National Cyber Security Forum. Lagos</source>
          . Nigeria
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Huang</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ma</surname>
            <given-names>S</given-names>
          </string-name>
          and
          <string-name>
            <surname>Chen</surname>
            <given-names>K.</given-names>
          </string-name>
          , (
          <year>2011</year>
          ).
          <article-title>Using one-time passwords to prevent password phishing attacks</article-title>
          .
          <source>Journal of Network and Computer Applications</source>
          . Elsevier Press..
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Dhamija</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Tygar</surname>
            ,
            <given-names>J. D.</given-names>
          </string-name>
          (
          <year>2005</year>
          ).
          <article-title>The battle against phishing: Dynamic security skins</article-title>
          .
          <source>In Proceedings of the Symposium on Usable Privacy and Security (SOUPS)</source>
          .
          <volume>77</volume>
          -
          <fpage>88</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Lovet</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          <year>2009</year>
          .
          <article-title>Fighting cybercrime: technical, juridical and ethical challenges</article-title>
          .
          <source>Proceedings of the Virus Bulletin Conference.</source>
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Moghimi</surname>
            <given-names>M</given-names>
          </string-name>
          and
          <string-name>
            <surname>Varjani</surname>
            <given-names>A.Y.</given-names>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>New rule-based phishing detection method</article-title>
          .
          <source>Journal of Expert Systems with Applications</source>
          . Vol
          <volume>53</volume>
          pp.
          <fpage>231</fpage>
          -
          <lpage>242</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Mohammed</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Furkan</surname>
            <given-names>A.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Sonia</surname>
            <given-names>C.</given-names>
          </string-name>
          <year>2015</year>
          .
          <article-title>Why phishing still works: User strategies for combating phishing attacks</article-title>
          .
          <source>International Journal of Human-Computer Studies</source>
          . Volume
          <volume>82</volume>
          . pp.
          <fpage>70</fpage>
          -
          <lpage>82</lpage>
          . Elsevier Press
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Maurer</surname>
            <given-names>M</given-names>
          </string-name>
          and
          <string-name>
            <surname>Hofer</surname>
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>Sophisticated Phishers Make More Spelling Mistakes: Using URL Similarity Against Phishing</article-title>
          . Springer.
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Ofuonye</surname>
            <given-names>E</given-names>
          </string-name>
          and
          <string-name>
            <surname>Miller</surname>
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>Securing web-clients with instrumented code and dynamic runtime monitoring</article-title>
          .
          <source>Journal of Systems and Software.</source>
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Pan</surname>
            <given-names>Y</given-names>
          </string-name>
          and
          <string-name>
            <surname>Ding</surname>
            <given-names>X.</given-names>
          </string-name>
          <year>2006</year>
          .
          <article-title>Anomaly based web phishing page detection</article-title>
          .
          <source>Proc. of the 22nd annual computer security applications conference.</source>
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Parno</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuo</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Perrig</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <year>2006</year>
          .
          <article-title>Phoolproof phishing prevention</article-title>
          .
          <source>Financial Cryptography and Data Security, Lecture Notes in Computer Science</source>
          , Vol.
          <volume>4107</volume>
          , Springer, Berlin.
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>Purkait</surname>
            <given-names>S.</given-names>
          </string-name>
          <year>2012</year>
          .
          <article-title>Phishing counter measures and their effectiveness- literature review</article-title>
          .
          <source>Information Management and Computer</source>
          Security Vol.
          <volume>20</volume>
          No. 5.
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <surname>Prakash</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kumar</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kompella</surname>
            ,
            <given-names>R.R.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Gupta</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2010</year>
          ).
          <article-title>Phishnet: predictive blacklisting to detect phishing attacks</article-title>
          .
          <source>Proceedings of the 29th Conference on Information Communications</source>
          , San Diego, CA, USA, pp.
          <fpage>346</fpage>
          -
          <lpage>50</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <surname>Ramanathan</surname>
            <given-names>V</given-names>
          </string-name>
          and
          <string-name>
            <surname>Wechsler</surname>
            <given-names>H.</given-names>
          </string-name>
          <year>2013</year>
          .
          <article-title>Phishing detection and impersonated entity discovery using Conditional Random Field and Latent Dirichlet Allocation</article-title>
          .
          <source>Journal of Computers and Security.</source>
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Ralf</surname>
            <given-names>K</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Peter</surname>
            <given-names>F</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Wolfgang</surname>
            <given-names>N.</given-names>
          </string-name>
          <year>2009</year>
          .
          <article-title>Latent Dirichlet Allocation for Tag Recommendation</article-title>
          .
          <source>Proc. of RecSys ACM.</source>
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>RSA</given-names>
            <surname>Anti-Fraud Command</surname>
          </string-name>
          <article-title>Center</article-title>
          .
          <source>RSA monthly online fraud report</source>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <surname>Shahriar</surname>
            <given-names>H</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zulkernine</surname>
            <given-names>M.</given-names>
          </string-name>
          <year>2011</year>
          .
          <article-title>Trustworthiness testing of phishing websites: a behavior model-based approach</article-title>
          .
          <source>Future Generation Computer Systems.</source>
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <surname>Sheng</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Holbrook</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kumaraguru</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cranor</surname>
            ,
            <given-names>L.F.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Downs</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <year>2010</year>
          .
          <article-title>Who falls for phish? A demographic analysis of phishing susceptibility and effectiveness of interventions</article-title>
          .
          <source>Proc. of the 28th International Conference on Human Factors in Computing Systems</source>
          , USA.
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <surname>Xiang</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hong</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rose</surname>
            ,
            <given-names>C.P.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Cranor</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <year>2011</year>
          CANTINA+
          <article-title>: a feature-rich machine learning framework for detecting phishing web sites</article-title>
          .
          <source>ACM Transactions on Information and System Security</source>
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <surname>Yue</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          <year>2010</year>
          .
          <article-title>BogusBiter: a transparent protection against phishing attacks</article-title>
          .
          <source>ACM Transactions on Internet Technology</source>
          , Vol.
          <volume>10</volume>
          No.
          <issue>2</issue>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>31</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <surname>Zhang</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Egelman</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cranor</surname>
            <given-names>L.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Hong</surname>
            <given-names>J.</given-names>
          </string-name>
          <year>2007</year>
          .
          <article-title>Phishing Phish: Evaluating Anti-Phishing Tools</article-title>
          .
          <source>Proc. of Network and Distributed Systems Security Symposium (NDSS)</source>
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [35]
          <string-name>
            <surname>Zhang</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          , Liu,
          <string-name>
            <given-names>G.</given-names>
            ,
            <surname>Chow</surname>
          </string-name>
          ,
          <string-name>
            <surname>T.W.S.</surname>
          </string-name>
          and Liu,
          <string-name>
            <surname>W.</surname>
          </string-name>
          <year>2011</year>
          .
          <article-title>Textual and visual content-based anti-phishing: a Bayesian approach</article-title>
          .
          <source>IEEE Transactions on Neural Networks</source>
          , Vol.
          <volume>2</volume>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>