论文标题
Phishchain:一个分散透明的系统到黑名单网络钓鱼URL
PhishChain: A Decentralized and Transparent System to Blacklist Phishing URLs
论文作者
论文摘要
黑名单是一种广泛使用的互联网安全机制,可保护互联网用户免受基于黑名单URL的财务骗局,恶意网页和其他网络攻击。在此演示中,我们将Phishchain(一种透明且分散的系统介绍给黑名单的网络钓鱼URL。目前,公共/私人领域黑名单,例如Phishtank,CryptoscamDB和APWG,是由集中权威维持的,但以人群采购的方式进行操作,以定期创建手动验证的黑名单。除了是单个故障之外,这种系统使用的黑名单过程是不透明的。我们利用区块链技术来支持透明度和权力下放,在那里没有一个机构控制黑名单,并且所有操作都记录在不变的分布式分类帐中。此外,我们设计了一个基于页面等级的真实发现算法,以根据人群来源的URL评估为每个URL分配网络钓鱼评分。作为自愿参与的动力,我们根据每个用户参与URL验证为每个用户分配技能点。
Blacklists are a widely-used Internet security mechanism to protect Internet users from financial scams, malicious web pages and other cyber attacks based on blacklisted URLs. In this demo, we introduce PhishChain, a transparent and decentralized system to blacklisting phishing URLs. At present, public/private domain blacklists, such as PhishTank, CryptoScamDB, and APWG, are maintained by a centralized authority, but operate in a crowd sourcing fashion to create a manually verified blacklist periodically. In addition to being a single point of failure, the blacklisting process utilized by such systems is not transparent. We utilize the blockchain technology to support transparency and decentralization, where no single authority is controlling the blacklist and all operations are recorded in an immutable distributed ledger. Further, we design a page rank based truth discovery algorithm to assign a phishing score to each URL based on crowd sourced assessment of URLs. As an incentive for voluntary participation, we assign skill points to each user based on their participation in URL verification.