Smishing Detector: A security model to detect smishing through SMS content analysis and URL behavior analysis.

Saved in:
Bibliographic Details
Title: Smishing Detector: A security model to detect smishing through SMS content analysis and URL behavior analysis.
Authors: Mishra, Sandhya1 (AUTHOR) sandhyashankar20@gmail.com, Soni, Devpriya1 (AUTHOR)
Source: Future Generation Computer Systems. Jul2020, Vol. 108, p803-815. 13p.
Subjects: Uniform Resource Locators, Behavioral assessment, Text messages, Naive Bayes classification, World Wide Web, Content analysis, Detectors
Abstract: Smartphone's popularity and their constant connectivity to the World Wide Web have made these devices vulnerable to phishing and smishing attacks. Phishing is a practice of sending malicious emails to users. Smishing is a combined form of SMS and Phishing in which invaders send SMS containing malicious content to the victim. This content sometimes includes links which redirect the user to websites containing malicious applications and user interfaces. Researchers have proposed various methods in past years to detect smishing but still, we lack a method that significantly avoids false-positive results i.e. falsely categorizing a message as malicious when it is genuine. Hence, we have proposed a model called 'Smishing Detector' to identify smishing messages while reducing false-positive results at every possible step. The proposed method consists of four modules, namely, SMS Content Analyzer, URL Filter, Source Code Analyzer and Apk Download Detector. SMS Content Analyzer analyzes the text message contents. Naive Bayes Classification Algorithm is used to identify the malicious contents and keywords present in the text message. URL Filter inspects the URL to identify malicious features. Source Code Analyzer examines the source code of the website to identify the harmful code embedded in it. Form tag and URL domain present in the source code are also inspected in this module. APK Download Detector identifies whether any malicious file is downloaded while invoking the URL. User consent taken while downloading the file is also inspected in this module. Finally, we have developed a prototype of the proposed system which has been validated with experiments on SMS datasets. In this paper, we have demonstrated the results of each module separately and also we have demonstrated the final results. The results of the experiments show an overall accuracy of 96.29%. We have compared this model with other models proposed by various researchers and we have found that this model covers more security aspects as compared to other models. • An efficient model titled 'Smishing Detector' to detect and block Smishing attacks. • APK Download Detector module to verify the URL in SMS. • Reduces false-positive results by using efficient techniques. • A user interface to skip the steps involved in detecting the Smishing SMS. • A prototype of the system is developed for real-time application. [ABSTRACT FROM AUTHOR]
Copyright of Future Generation Computer Systems is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 142814674
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Smishing Detector: A security model to detect smishing through SMS content analysis and URL behavior analysis.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Mishra%2C+Sandhya%22">Mishra, Sandhya</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> sandhyashankar20@gmail.com</i><br /><searchLink fieldCode="AR" term="%22Soni%2C+Devpriya%22">Soni, Devpriya</searchLink><relatesTo>1</relatesTo> (AUTHOR)
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Future+Generation+Computer+Systems%22">Future Generation Computer Systems</searchLink>. Jul2020, Vol. 108, p803-815. 13p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Uniform+Resource+Locators%22">Uniform Resource Locators</searchLink><br /><searchLink fieldCode="DE" term="%22Behavioral+assessment%22">Behavioral assessment</searchLink><br /><searchLink fieldCode="DE" term="%22Text+messages%22">Text messages</searchLink><br /><searchLink fieldCode="DE" term="%22Naive+Bayes+classification%22">Naive Bayes classification</searchLink><br /><searchLink fieldCode="DE" term="%22World+Wide+Web%22">World Wide Web</searchLink><br /><searchLink fieldCode="DE" term="%22Content+analysis%22">Content analysis</searchLink><br /><searchLink fieldCode="DE" term="%22Detectors%22">Detectors</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Smartphone's popularity and their constant connectivity to the World Wide Web have made these devices vulnerable to phishing and smishing attacks. Phishing is a practice of sending malicious emails to users. Smishing is a combined form of SMS and Phishing in which invaders send SMS containing malicious content to the victim. This content sometimes includes links which redirect the user to websites containing malicious applications and user interfaces. Researchers have proposed various methods in past years to detect smishing but still, we lack a method that significantly avoids false-positive results i.e. falsely categorizing a message as malicious when it is genuine. Hence, we have proposed a model called 'Smishing Detector' to identify smishing messages while reducing false-positive results at every possible step. The proposed method consists of four modules, namely, SMS Content Analyzer, URL Filter, Source Code Analyzer and Apk Download Detector. SMS Content Analyzer analyzes the text message contents. Naive Bayes Classification Algorithm is used to identify the malicious contents and keywords present in the text message. URL Filter inspects the URL to identify malicious features. Source Code Analyzer examines the source code of the website to identify the harmful code embedded in it. Form tag and URL domain present in the source code are also inspected in this module. APK Download Detector identifies whether any malicious file is downloaded while invoking the URL. User consent taken while downloading the file is also inspected in this module. Finally, we have developed a prototype of the proposed system which has been validated with experiments on SMS datasets. In this paper, we have demonstrated the results of each module separately and also we have demonstrated the final results. The results of the experiments show an overall accuracy of 96.29%. We have compared this model with other models proposed by various researchers and we have found that this model covers more security aspects as compared to other models. • An efficient model titled 'Smishing Detector' to detect and block Smishing attacks. • APK Download Detector module to verify the URL in SMS. • Reduces false-positive results by using efficient techniques. • A user interface to skip the steps involved in detecting the Smishing SMS. • A prototype of the system is developed for real-time application. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Future Generation Computer Systems is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=142814674
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1016/j.future.2020.03.021
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 13
        StartPage: 803
    Subjects:
      – SubjectFull: Uniform Resource Locators
        Type: general
      – SubjectFull: Behavioral assessment
        Type: general
      – SubjectFull: Text messages
        Type: general
      – SubjectFull: Naive Bayes classification
        Type: general
      – SubjectFull: World Wide Web
        Type: general
      – SubjectFull: Content analysis
        Type: general
      – SubjectFull: Detectors
        Type: general
    Titles:
      – TitleFull: Smishing Detector: A security model to detect smishing through SMS content analysis and URL behavior analysis.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Mishra, Sandhya
      – PersonEntity:
          Name:
            NameFull: Soni, Devpriya
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 07
              Text: Jul2020
              Type: published
              Y: 2020
          Identifiers:
            – Type: issn-print
              Value: 0167739X
          Numbering:
            – Type: volume
              Value: 108
          Titles:
            – TitleFull: Future Generation Computer Systems
              Type: main
ResultId 1