Skip to main content
QUICK REVIEW

[论文解读] Early Phishing

Koceilah Rekouche|arXiv (Cornell University)|Jun 23, 2011
Spam and Phishing Detection被引用 5
一句话总结

本文追溯了网络钓鱼的起源至1990年代中期,指出作者开发的AOHell——首个公开可用的自动化工具,用于在美国在线(America Online)上窃取密码和信用卡信息——标志着网络钓鱼现象的诞生。文章记录了这一早期系统如何演变为广泛存在的网络犯罪威胁,影响了数代由业余爱好者及后来的专业网络罪犯使用的自动化网络钓鱼工具。

ABSTRACT

The history of phishing traces back in important ways to the mid-1990s when hacking software facilitated the mass targeting of people in password stealing scams on America Online (AOL). The first of these software programs was mine, called AOHell, and it was where the word phishing was coined. The software provided an automated password and credit card-stealing mechanism starting in January 1995. Though the practice of tricking users in order to steal passwords or information possibly goes back to the earliest days of computer networking, AOHell's phishing system was the first automated tool made publicly available for this purpose. The program influenced the creation of many other automated phishing systems that were made over a number of years. These tools were available to amateurs who used them to engage in a countless number of phishing attacks. By the later part of the decade, the activity moved from AOL to other networks and eventually grew to involve professional criminals on the internet. What began as a scheme by rebellious teenagers to steal passwords evolved into one of the top computer security threats affecting people, corporations, and governments.

研究动机与目标

  • 追溯1990年代中期网络钓鱼作为网络犯罪手段的历史起源。
  • 确立AOHell为首个公开可用的自动化工具,用于窃取用户凭证和财务数据。
  • 记录使用AOHell的业余黑客如何开创一种趋势,该趋势后来演变为有组织的专业网络钓鱼行动。
  • 分析早期自动化网络钓鱼工具对现代网络威胁的长期影响。
  • 强调从青少年恶作剧到针对个人、企业及政府的大规模攻击的转变过程。

提出的方法

  • 开发并部署AOHell,一款专为在美国在线上自动化窃取密码和信用卡信息而设计的定制软件工具。
  • 实施自动化机制,通过社交工程手段大规模识别并利用用户账户。
  • 首次将术语'phishing'与这一自动化凭证窃取过程联系起来。
  • 向广大用户群体分发AOHell,使非技术用户也能实施网络钓鱼攻击。
  • 观察该工具对后续各类在线网络中自动化网络钓鱼工具开发的影响。
  • 追踪网络钓鱼活动从AOL向更广泛的互联网平台迁移的过程,随着技术传播而扩展。

实验结果

研究问题

  • RQ1首个专为大规模窃取密码和信用卡信息而设计的自动化工具是什么,何时被创建?
  • RQ2AOHell的开发在多大程度上促成了术语'phishing'的正式确立与普及?
  • RQ3AOHell以何种方式使非技术用户能够参与网络犯罪?
  • RQ4网络钓鱼攻击的性质如何从个人化的业余行为演变为有组织的专业网络犯罪?
  • RQ5像AOHell这样的早期工具在塑造现代网络钓鱼威胁方面发挥了什么作用?

主要发现

  • AOHell于1995年1月创建,是首个在America Online上公开可用的自动化工具,用于窃取密码和信用卡信息。
  • 术语'phishing'首次与AOHell关联,标志着该概念在网络安全史上的正式出现。
  • 该工具使业余用户能够实施大规模凭证窃取,显著降低了网络犯罪的参与门槛。
  • 网络钓鱼从叛逆青少年的恶作剧演变为针对个人、企业及政府的重大威胁。
  • AOHell的成功与传播激发了互联网上众多类似自动化网络钓鱼系统的开发。
  • 1990年代末从AOL向更广泛互联网平台的迁移,标志着网络钓鱼发展为全球性网络威胁。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。