A Content-Based Approach for Detecting Smishing in Mobile Environment

8 Pages Posted: 12 Jun 2019 Last revised: 16 Apr 2019

See all articles by Sandhya Mishra

Sandhya Mishra

Jaypee Institute of Information Technology (JIIT)

Devpriya Soni

Jaypee Institute of Information Technology (JIIT)

Date Written: February 23, 2019

Abstract

Rapid development in Information Technology has led to increased usage of smartphones. Smartphone users are storing their sensitive information like their user credentials, credit card, and debit card information in the mobile device. Moreover, mobile devices are constantly connected to the World Wide Web through packet data connection or Wifi which makes these devices prone to phishing attacks. Smishing is a combination of Sms and Phishing in which attackers target the mobile user through a text message sent to their mobile device. These text messages contain a link which will redirect the user to malicious websites. Many methods are proposed by researchers in past years to mitigate the smishing attacks which included SMS feature-based analysis, blacklisting techniques, and heuristic methods. But still, we don't have a method which reduces false positive results. Hence, We have proposed a novel method which will categorize the text message based on the SMS contents and URL behavior. SMS content analysis is performed using text pre-processing and analyzing techniques to detect the presence of URL, Phone Number, E-mail ID, and malicious keywords in the message. We have used a machine learning algorithm to classify the message on basis of malicious keywords present in the message. We have also used the techniques of form tag check and APK download check to analyze the malicious behavior of the URL. Text messages will be finally classified into a malicious and non-malicious category based on the results of the detection techniques.

Keywords: Smishing, Phishing, Text Messaging, Machine Learning, Mobile Security, SMS Short Message Service

Suggested Citation

Mishra, Sandhya and Soni, Devpriya, A Content-Based Approach for Detecting Smishing in Mobile Environment (February 23, 2019). Proceedings of International Conference on Sustainable Computing in Science, Technology and Management (SUSCOM), Amity University Rajasthan, Jaipur - India, February 26-28, 2019, Available at SSRN: https://ssrn.com/abstract=3356256 or http://dx.doi.org/10.2139/ssrn.3356256

Sandhya Mishra (Contact Author)

Jaypee Institute of Information Technology (JIIT) ( email )

Devpriya Soni

Jaypee Institute of Information Technology (JIIT) ( email )

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
1,112
Abstract Views
3,613
Rank
48,791
PlumX Metrics