作者
Peng Peng, Limin Yang, Linhai Song, Gang Wang
发表日期
2019/10/21
图书
Proceedings of the Internet Measurement Conference
页码范围
478-485
简介
Online scan engines such as VirusTotal are heavily used by researchers to label malicious URLs and files. Unfortunately, it is not well understood how the labels are generated and how reliable the scanning results are. In this paper, we focus on VirusTotal and its 68 third-party vendors to examine their labeling process on phishing URLs. We perform a series of measurements by setting up our own phishing websites (mimicking PayPal and IRS) and submitting the URLs for scanning. By analyzing the incoming network traffic and the dynamic label changes at VirusTotal, we reveal new insights into how VirusTotal works and the quality of their labels. Among other things, we show that vendors have trouble flagging all phishing sites, and even the best vendors missed 30% of our phishing sites. In addition, the scanning results are not immediately updated to VirusTotal after the scanning, and there are inconsistent …
引用总数
学术搜索中的文章
P Peng, L Yang, L Song, G Wang - Proceedings of the Internet Measurement Conference, 2019