Phishing & BotNets
RE: early detection Jan 06 2006 11:45PM
Compton, Rich (richard compton chartercom com)
FYI, TippingPoint also has some nice filters that prevent Phishing
attacks at the network layer. They have a nice pdf white paper about

Most anti-phishing work these days is done on the client side, but there
is a decent push underway to track and protect from these on the server
side. A few examples:

- has a few rules for snort that pull from and
block known phishing domains. These rules can easily be reworked for
your particular firewall/IPS/IDS device.

- An excellent phishing news database;
also hosts one of the domain lists referenced above.

- There has been some good work in web application firewall space
recently to protect sites and content owners from phishing linking and
data mining.

<shameless-plug> F5 has a method for protecting against these types of
intellectual property attacks before they get to the content servers
(posted in our development community forum):



There are other vendors doing similar work in the WAF space as well, but
I'll leave those for your google'ing enjoyment... ;)

Hope this helps...take care...

Hi All,
I have two questions:
1)What are the early detection techniques used by companies to
determine/monitor phishing sites.
2) What are the techniques used for link analysis to fight phishing or
Are these tools available for users or they are specific for large
institutions. Is there a way to do experiments on them?
I know both questions might be broad but I want to have an idea.


