Blacklists are a widely-used Internet security mechanism to protect Internet users from financial scams, malicious web pages and other cyber attacks based on blacklisted URLs. In this demo, we introduce PhishChain, a transparent and decentralized system to blacklisting phishing URLs. At present, public/private domain blacklists, such as PhishTank, CryptoScamDB, and APWG, are maintained by a centralized authority, but operate in a crowd sourcing fashion to create a manually verified blacklist periodically. In addition to being a single point of failure, the blacklisting process utilized by such systems is not transparent. We utilize the blockchain technology to support transparency and decentralization, where no single authority is controlling the blacklist and all operations are recorded in an immutable distributed ledger. Further, we design a page rank based truth discovery algorithm to assign a phishing score to each URL based on crowd sourced assessment of URLs. As an incentive for voluntary participation, we assign skill points to each user based on their participation in URL verification.
翻译:黑名单是一种广泛使用的互联网安全机制,目的是保护互联网用户免遭金融骗局、恶意网页和其他基于黑名单的网络攻击。 在这个演示中,我们引入了Phish Chain,这是一个透明、分散的黑名单系统,用于将网友列入黑名单。目前,公共/私人域域名黑名单,如PhishTank、CryptoScamDB和APWG, 由中央管理机构维持,但以众包方式运作,定期制作一个人工核查的黑名单。除了一个单一的失败点外,这些系统使用的黑名单程序也不透明。我们利用连锁技术支持透明度和分散化,在这个系统中,没有单一的当局控制黑名单,所有业务都记录在不可变更的分布分类账簿中。此外,我们设计了一个基于真相发现算法的页页码,根据对URL的众源评估,为每个网民提供钓分。为了鼓励自愿参与,我们还根据每个用户参与URL核查情况,为每个用户指定了技术点。