| Item type |
Symposium(1) |
| 公開日 |
2025-10-20 |
| タイトル |
|
|
言語 |
ja |
|
タイトル |
商品画像検索による偽ショッピングサイトURL収集方式の提案と実態調査 |
| タイトル |
|
|
言語 |
en |
|
タイトル |
Proposal and Empirical Study on Fake Shopping Website URL Collection via Product Image Search |
| 言語 |
|
|
言語 |
jpn |
| キーワード |
|
|
主題Scheme |
Other |
| 資源タイプ |
|
|
資源タイプ識別子 |
http://purl.org/coar/resource_type/c_5794 |
|
資源タイプ |
conference paper |
| 著者所属 |
|
|
|
国立研究開発法人情報通信研究機構 |
| 著者所属 |
|
|
|
国立研究開発法人情報通信研究機構 |
| 著者所属 |
|
|
|
国立研究開発法人情報通信研究機構 |
| 著者所属 |
|
|
|
国立研究開発法人情報通信研究機構 |
| 著者所属 |
|
|
|
国立研究開発法人情報通信研究機構 |
| 著者所属 |
|
|
|
国立研究開発法人情報通信研究機構 |
| 著者所属(英) |
|
|
|
National Institute of Information and Communications Technology |
| 著者所属(英) |
|
|
|
National Institute of Information and Communications Technology |
| 著者所属(英) |
|
|
|
National Institute of Information and Communications Technology |
| 著者所属(英) |
|
|
|
National Institute of Information and Communications Technology |
| 著者所属(英) |
|
|
|
National Institute of Information and Communications Technology |
| 著者所属(英) |
|
|
|
National Institute of Information and Communications Technology |
| 著者名 |
吉井,優輝
川村,慎太郎
中村,渚
田中,秀一
安田, 真悟
井上, 大介
|
| 著者名(英) |
Masaki Yoshii
Shintaro Kawamura
Nagisa Nakamura
Hidekazu Tanaka
Shingo Yasuda
Daisuke Inoue
|
| 論文抄録 |
|
|
内容記述タイプ |
Other |
|
内容記述 |
フィッシングサイトの 1 つとして,正規のショッピングサイトを模倣した偽ショッピングサイトの存在が挙げられる.このようなサイトは,購入者の金銭,クレジットカード情報や個人情報の搾取を目的としている.また正規ショッピングサイトなどの掲載商品画像を無断転載していることも確認されている.フィッシングサイトは,正規サイトに不正アクセスしリダイレクト用スクリプトを仕込み踏み台とすることで,正規サイトにアクセスしたユーザを誘導する.同時に Web 検索エンジンの検索結果を不正に操作する SEO ポイズニングにより,ユーザのフィッシングサイトへのアクセスがより増加しやすくなる.上記の背景から,NICT ではユーザに Web センサとしてタチコマ・セキュリティ・エージェントと呼称するアプリケーションを配布し,Web アクセスログを収集し,Web 媒介型攻撃の観測・分析を実施してきた.本取り組みは WarpDrive プロジェクトと呼称し,ユーザによる Web アクセスを主としたデータ収集を通じて受動的な Web 媒介型攻撃観測を可能とする.フィッシングサイトとはじめとする悪性サイトは出現や削除のスパンが短いことからより能動的な悪性サイト情報収集を実施することで,悪性サイトの傾向分析やより多くの URL 情報獲得が可能と考えられる.本研究では,多くの悪性サイト URL を能動的に収集し解析性能向上を目的とする.ショッピングサイトでの商品閲覧時はほぼ確実に商品画像を閲覧すること,多くの偽ショッピングサイトでは同じ商品画像の使いまわしが行われている.そこで,本稿では偽ショッピングサイトを対象に掲載された商品画像をシードとし,Google Cloud Vision API を用いた類似画像掲載サイトの URL 収集の実施,リダイレクト前・リダイレクト後の URL の収集の方式を提案する.実際に,偽ショッピングサイトと疑われるサイトの商品画像 426 枚を用いて実態調査を実施したため報告する. |
| 論文抄録(英) |
|
|
内容記述タイプ |
Other |
|
内容記述 |
Among the various forms of phishing websites, one prominent example is fake shopping websites that imitate legitimate e-commerce platforms. These fraudulent sites are primarily designed to exploit consumers by stealing money, credit card details, and personal information. It has also been confirmed that such sites frequently engage in the unauthorized reproduction of product images originally published on legitimate shopping platforms. Furthermore, phishing websites often lure users by embedding redirect scripts into compromised legitimate sites, thereby turning them into stepping stones. In addition, by manipulating search engine rankings through SEO poisoning, the likelihood of unsuspecting users being directed to these malicious websites is further increased. To address these threats, the National Institute of Information and Communications Technology (NICT) has developed and distributed an application called the Tachikoma Security Agent, which functions as a Web sensor for users. By collecting web access logs, NICT has been able to observe and analyze Web-based attacks as part of an initiative known as the WarpDrive Project. This project primarily relies on passive data collection from user web activity, thereby enabling large-scale monitoring of Web-mediated cyber threats. However, because phishing and other malicious websites tend to emerge and disappear within short timeframes, a more active approach to collecting malicious site information is expected to enable more effective trend analysis and the acquisition of a wider range of URL data. In this study, we aim to actively collect a large number of malicious website URLs to enhance analytical performance. Since product images are almost invariably viewed during e-commerce browsing sessions, and because fake shopping websites often recycle identical product images, we propose a technique that uses these product images as seeds for malicious site detection. Specifically, the proposed method leverages the Google Cloud Vision API to identify and collect URLs of websites hosting visually similar images, including both pre-redirect and post-redirect URLs. Based on this approach, we conducted an empirical investigation using 426 product images obtained from suspected fake shopping websites, and we report the results in this paper. |
| 書誌情報 |
コンピュータセキュリティシンポジウム2025論文集
p. 2007-2014,
発行日 2025-10-20
|
| 出版者 |
|
|
言語 |
ja |
|
出版者 |
情報処理学会 |