Monday, April 21, 2025

When Passion Fades: The Struggle Between Obligation and Desire

There’s a noticeable difference in how I feel when I’m doing something I genuinely want to do, versus when I’m just completing a task someone gave me. I think I first became aware of this during my third year of college. At that point, I had a mountain of assignments—some from class, others from research projects. They weren’t particularly difficult, but something felt off.

The problem wasn’t the workload. It was the lack of continuity. Once I completed an assignment, I didn’t feel motivated to keep going or explore further. It was like my brain flipped a switch: task done, now shut down. There was no internal drive to go beyond the bare minimum, and honestly, if it weren’t for the looming deadlines, I probably wouldn’t have done them at all.

And that word—deadline—has always rubbed me the wrong way. It felt cold, mechanical. To me, you should want to do something because you’re curious, excited, or passionate—not simply because someone told you to do it within a set timeframe.

This frustration with external expectations isn’t new. I’ve always compared the energy I put into "deadline tasks" with the flow I get when I’m doing things just because I feel like it. This blog post is part of a series where I’m trying to understand why some activities spark enthusiasm and creativity, while others—no matter how small—drain me completely.

At one point, I wondered if my attention span was wrecked by smartphone addiction. I tried forcing myself to cut back, but that didn’t solve anything. If something is truly engaging, it should easily compete with mindless scrolling or random cat videos. Yet somehow, it didn’t.

I’ve also steered clear of motivational videos. They might give you a quick jolt of inspiration, but it’s short-lived. They don't offer sustainable change, at least not for me.

Interestingly, I heard Magnus Carlsen talk about this on the Joe Rogan podcast. He said he loved playing chess for the sake of it, but lost interest when his coach started giving him arbitrary training assignments. It became a chore, and the joy disappeared. I related to that deeply. Not that I’m on Carlsen’s level, but I think the core issue is similar: when something doesn’t come from within, it doesn’t feel like mine. And maybe that’s the trick—maybe the key to doing something wholeheartedly is feeling like you chose it yourself.

It reminds me of the difference between walking and being pushed. If you're walking on your own path—even if it's uphill—you’re in control of the pace, the direction, and the purpose. But if someone’s behind you, pushing you forward, the same walk suddenly feels heavier, even if the terrain hasn’t changed. The weight isn’t in your legs—it’s in your mind.

This also shows up in creative projects. I remember a time when I spontaneously started learning to sketch. I was excited, watching tutorials, practicing lines, losing hours in that beautiful zone where time disappears. But the moment I signed up for a structured online course with weekly assignments and “feedback deadlines,” the excitement vanished. It felt like I’d turned my hobby into homework.

And maybe that’s where the deeper question lies: how do we protect the joy in what we do? How do we keep something from becoming an obligation, even if it needs structure? Perhaps the answer is less about rejecting discipline and more about owning it. Choosing your own deadlines. Setting your own goals. Making the work feel like an extension of your interests, not a disruption of them.

Sometimes I think the answer is in curiosity. When you’re curious, you're not chasing a goal—you’re just exploring. Like a child digging through sand, not trying to build a castle, just fascinated by what’s beneath. That energy is different. It’s sustainable. And it’s fulfilling in a way that “finishing tasks” never is.

So I’m still figuring it out—how to keep that spark alive. How to balance the things I must do with the things I want to do, and ideally make the two overlap more often. Until then, I’ll keep writing, reflecting, and trying to notice the difference between walking freely and being pushed.

Tuesday, February 11, 2025

Why ‘Liking’ Something Might Be an Illusion


I've had friends tell me they "really like programming," and that statement stuck with me. At times, I felt the same way myself.

After completing a project—like building my own version of Tetris or a simple To-Do app using a newly discovered graphics library—I would feel a strong sense of enjoyment for programming. But by the next day, that excitement would fade. This phenomenon never quite made sense to me. Isn’t "liking" something supposed to be a long-term feeling? At least, that's how I always thought it should work.

Recently, however, I had an insight that helped clarify this contradiction. What if it's impossible to "like" doing something in itself? If that were true, it would mean that even "liking to do good for the community" isn’t a real thing—which might sound strange, but let me explain.

I now believe that instead of liking an activity itself, what we actually enjoy is doing that activity well. This idea makes more sense when considering how humans, like all living beings, rely on feedback from their environment to gauge success and progress.

Think about the first time you try to understand how integrated circuits work. At first, the green tracks on the chip seem meaningless. But then you learn that they transfer electricity to different parts of the chip, making the whole system function. You go from knowing nothing to understanding something significant—your learning rate is practically infinite. Since you improved so quickly, it feels great, and you might conclude that you "really like electronics." But what you actually enjoy is learning electronics well. Later, when you dive into more complex topics like energy bands, the process is much slower and frustrating. Suddenly, you don’t "like" it as much anymore.

Here’s a more practical example: I tried surfing three times in my life. The first time, I actively focused on improvement, applying techniques I had seen in a YouTube video. The result? I did surprisingly well, and my brain told me, "I like surfing!" But on my second and third attempts, I felt more relaxed, assuming I had already grasped the basics. However, without muscle memory to reinforce my previous learning, my technique declined. I mispositioned my feet, mistimed the waves, and struggled more than before. My brain now told me the opposite: "I don't like surfing."

These examples suggest that people generally enjoy doing things well rather than just doing them. This perspective also explains a common behavioral pattern: people tend to overestimate their abilities and progress. Initially, I saw this as a flaw, but now I wonder if it might be beneficial. If we need to feel competent to enjoy an activity, then those who overestimate themselves may be more inclined to pursue and stick with new challenges simply because they believe they’re good at them.

This argument challenges the idea that humility is always a virtue. According to this hypothesis, excessive humility could be detrimental—it might prevent someone from recognizing their own competence, thereby reducing their motivation to continue. On the other hand, extreme overconfidence can lead to arrogance and social issues. The ideal balance lies somewhere in between: acknowledging progress without becoming overconfident.

One lingering question remains: Does "doing well" always require comparison? If so, that would explain why Chris Pratt’s character in Passengers became so bored over time—without anyone to compare himself to, he lost a sense of achievement. But even without direct comparison, I believe people can still enjoy activities if they see personal growth and improvement.

With all that said, the next time you hear someone say, "I like doing this," it might be worth asking: What exactly do they like? Is it the activity itself—or the feeling of doing it well?

Sunday, October 20, 2024

The Science of Cravings: Why the First Bite Always Wins


Have you ever finished a delicious meal and suddenly craved a piece of chocolate? That craving arises because the pleasure of eating has ended, and your brain, eager to maintain stimulation, searches for the next source of enjoyment.

Humans naturally seek activities that make them feel good. The brain measures "feeling good" by the amount of hormones—such as dopamine—circulating in it. To maintain a steady flow, it constantly directs us toward actions that maximize these hormones. In the case of chocolate, once the meal is over, the brain instinctively searches for something else that provides a similar or greater level of satisfaction. Chocolate often emerges as an appealing choice.

However, the first bite of chocolate is always more satisfying than the last. This is because the brain self-regulates, signaling, "That's enough, move on to something else." From an evolutionary perspective, this mechanism is crucial. If early humans fixated on only one pleasurable activity, such as building shelters, they wouldn’t have diversified their skills to include hunting, farming, and socializing. To promote variety, the brain gradually reduces the reward response to repetitive tasks over time.

This pattern also appears in everyday activities like studying or working. Initially, you might feel motivated to start your homework to get it off your mind. But as time passes, that motivation fades, and your brain begins seeking alternative sources of stimulation—perhaps calling a friend, gardening, or grabbing a snack. This is simply your brain’s way of ensuring you remain engaged and hormonally balanced to facilitate learning and productivity.

In today’s digital world, the brain has an even easier time finding quick sources of stimulation. The first time you watch a hilarious cat video on Instagram Reels, your brain immediately registers Instagram as a reliable dopamine source. This memory persists because the brain dislikes being unstimulated for long, so it prioritizes recalling past activities that provided easy satisfaction. This explains the constant urge to open entertainment apps—your brain perceives your current task as less rewarding than simply watching more cat videos.

Similarly, consider a programmer debugging code. After hours of effort, a stubborn bug refuses to be solved. Frustrated, the brain—unable to generate satisfaction from failure—shifts its focus. Instead of intensifying problem-solving efforts, it searches for an immediate dopamine fix. That’s when you unconsciously reach for your phone, drawn toward the very distractions that momentarily ease your frustration.

Over time, this cycle becomes more pronounced. You might even receive a screen time notification, realizing how much time you've wasted on entertainment apps. Attempting to fight this urge by forcing yourself to focus entirely on work may succeed for a day, but exhaustion soon sets in, making the temptation to scroll through social media even stronger. The more your brain associates an app with an easy dopamine hit, the harder it becomes to resist.

Trying to fight this instinct head-on is like chopping wood with the blunt side of an axe—it’s ineffective and exhausting. A better approach is understanding why the brain works this way and using that knowledge to your advantage. Instead of simply uninstalling Instagram, a more sustainable solution is convincing yourself that it isn’t a genuine source of happiness. However, rewiring your brain isn’t easy. Since your neural pathways are already conditioned to seek stimulation from these apps, true change requires strong personal conviction.

On a final note, I was inspired to write this after hearing someone say they "needed" to watch TikTok videos to recharge from a tiring day. This made me reflect on the rabbit hole entertainment apps create. What that person didn’t realize was that the very thing they turned to for relief—TikTok—was actually contributing to their exhaustion in the first place.

Wednesday, October 16, 2024

The Silent Cost of Convenience: How Technology is Stealing Our Thinking Time


At first glance, the idea that technology is making us dumber seems absurd. How could something that enabled humanity to reach the Moon possibly be bad for us? And no, I’m not going to push the tired argument that saving phone numbers in our smartphones has made us incapable of memorizing them. Stick with me for a moment—I want to show you something deeper.

As my high school sociology teacher used to say, technology is anything that helps a living being accomplish a task. Cars assist us with transportation, phones enhance communication, and computers boost productivity. However, every technological advancement comes with a hidden trade-off: it transforms slow, time-consuming processes into instant, effortless ones. While this efficiency allows us to achieve more complex feats, we rarely stop to ask—were we designed to operate at this speed?

Consider this: the first Homo sapiens appeared around 300,000 years ago, but the earliest evidence of human creativity—art, trade, ornaments, and burial rites—only dates back about 30,000 years. Before even the invention of agriculture, daily life was simple. People spent time guarding their communities, walking long distances for food, and gathering firewood. The same brain that once handled these basic activities is now tasked with processing abstract concepts like algorithms and marketing strategies. Yet, human evolution never accounted for this sudden shift. Our brains were shaped in an environment where we had ample time to think, plan, and reflect.

In the past, the necessity of performing repetitive, slow tasks naturally created idle time. This downtime was crucial for considering options, envisioning the future, and generating ideas. As technology removes these monotonous activities from our daily lives, it also strips away the unstructured time our minds need to wander and reflect. Today, boredom has become a rare experience. Many people unknowingly seek refuge in the stillness of religious gatherings—not necessarily for faith alone, but because it might be the only hour of boredom they experience all week. The rest of their time is consumed by video calls, social media, and entertainment, leaving little room for deep contemplation.

Somewhere along the way, we lost the understanding that doing nothing—or engaging in slow, repetitive tasks—can actually be beneficial. These moments allow us to process life on a broader scale, fostering a sense of control and clarity. Yet, in a world where we can be stimulated at all times, the only chance we get to reflect is perhaps during a Sunday mass or while washing dishes. But how does a modern human, conditioned to constant engagement, even recognize that they might need seven hours of stillness—just like their ancestors had while farming the land?

Without this mental breathing room, I believe we’re witnessing a rise in psychological issues, driven by a lack of confidence and the inability to engage in meaningful long-term thinking. We’ve known this since WALL-E warned us about it, yet few people actually take the time to unplug and let their minds wander. Instead, we remain trapped in an endless cycle of short-term decisions, never allowing ourselves the space to truly think things through.

Technology has given us incredible advantages, but it has also stolen something fundamental: the ability to simply be with our own thoughts. And if we don’t start reclaiming that time, we might wake up one day to realize that, despite all our progress, we’ve forgotten how to truly think.

Monday, October 7, 2024

(Preliminary Results) Inside the Phishing Reel: Identifying phishing kits at scale

Introduction

In the first quarter of 2024, APWG reported an average of 300.000 unique monthly phishing attacks. Besides that, Microsoft Digital Defense Report also demonstrated that the problem is caused by the low-cost barrier in the phishing market due to the commercialization of phishing kits, which are code repositories that are created to mimic benign websites while redirecting information typed on the credentials fields to a centralized server, to be sold in the dark market later. Those phishing kits are made to be easily deployed by attackers at scale.

Besides all the efforts to classify phishing pages based on visual differences between malicious websites and their benign counterpart, we have a low study on the distribution of phishing kits and how they are deployed over time. One recent study tackled that by identifying a handful of phishing kits and manually identifying fingerprintable information in them, which later was used to identify which websites correspond to which phishing kits in the wild. Due to the phishing kits analyzed in this study being ones that are freely distributed in telegram channels, we argue that this approach only captures simple phishing samples, which might not be responsible for the majority of effective phishing attacks.

We managed to improve that by creating a mechanism that will identify phishing kits on a large scale by measuring their behavior at crawling time. That will enable the security analyst to group URLs that run the same code and consequently are deployed from the same phishing kit.

For that, we create a tool that completely bypasses code obfuscation, regardless of different obfuscations. And also proposes a spread view of the phishing landscape by analyzing crawler data over a long period of time (TODO), which besides understanding common practices and the duration period of phishing pages, will enable the analyst to see the evolutions of phishing pages, and hopefully assign different phishing pages to the same possible authors.

Finally, the tool also enables the analyst to verify which samples were never seen before in terms of client-side behavior. That will save valuable human resources as they receive thousands of phishing websites to be reviewed daily, and automatically filtering out the ones that were already seen decreases the amount of human wasted time.

Crawler


The most important part of the crawler is the browser. We used an instrumented version of Chromium with slight modifications to the bytecode generation pipeline and runtime function calling, to identify javascript property accesses and function calls. That browser allows us to see exactly which operations were executed by each website at runtime in a way that is impossible to identify from the website itself (which is the main advantage over the regular CDP approach). Our modifications follow previous studies that use the same technique on older versions of the browser.

To log function calling, we hook the runtime function calling method used inside Chromium. To log property access information we had to instrument the bytecode generation process and create an extra bytecode that calls a logging function whenever a property is loaded or stored with its information. We then moved this instrumented compiled version of Chromium to a docker container to make it scalable.

The log format created by the browser has the following characteristics. For each process created from the website that is being visited, one log file is created on the disk with the sequential instructions executed by the browser. Besides the instructions, the log file also contains information on the source code that was loaded before the instructions were executed. Also, it is possible to attribute the execution of each instruction to one specific script, loaded from a specific origin inside the V8 running context.

One of the key problems we have with phishing websites is that often phishing kits are obfuscated and sometimes with different tools. With that approach, we completely bypass obfuscation and even though the source code might look different due to different obfuscation techniques, the browser will see the exact same sequence of instructions being executed.

Besides, another problem phishing crawlers often have to handle is regarding cloaking, which is something we don't have to tackle here for a very nice reason. We want to cluster together websites that behave in the same way, which means that even though our browser is redirected due to cloaking, we still would be able to cluster together the websites that use cloaking the same way. In the end, we argue that it is enough information to identify phishing pages deployed from the same phishing kit (TODO).

In general, the full crawler works as follows. We have a module Trigger that runs twice a day, at linearly random times, which is important to avoid being cloaked by those platforms that do not support crawling. When it runs, it calls three other modules sequentially. First, it runs the Downloader modules, that try to access public-access sources of phishing URLs that are reported and validated by security analysts (those are PhishTank, OpenPhish, and PhishStats). After accessing the new URLs it then checks against a database of previously crawled URLs to avoid crawling the URL again. If there are any new URLs, the trigger runs the Analyzer module on those new URLs, which consists of running the Instrumented Browser on the URL for 10s, then a tool called Resources Saver to save the public resources of the page (such as images, icons, source code) and then KitPhishR, that is a tool that seeks phishing kits stored in the deployed phishing server. The browser is executed in a docker container that is created to analyze batches of 10 URLs, which is then destroyed to be replaced by another docker instance to analyze more samples.

Information on the resources and the phishing kits (obtained with KitPhishR) are not used in the processing pipeline. They will be used in a validation phase to verify if the phishing URLs assigned to the same cluster are indeed from the same phishing kit.

After the analysis is completed, we store the results of each URL in a separate directory that is named after the hash of the domain that was crawled, therefore using that to make sure that the same domain is not crawled twice. 

After the tool finishes to analyse the URLs, due to storage limitations in the server we have to upload all the sample results to the Google Drive, which stores all the samples separated by source, day and hour that was crawled.

Projector


With the logs in hand, we can run the projector once a day. This tool will verify for each day, which ones are similar to another one that has been seen before, and which one seems to be new.

Since we can't keep all the data on disk at the same time, the projector downloads the samples one day at a time, uses the Log Parser module to transform the log information of each sample into an Intermediary Representation of the logs, and then adds it to the dataset using the Dataset Parser module.

The Log Parser handles the logs by considering that each sample contains javascript code from n different sources during execution. Because of that, it breaks the single sequence of instructions produced by the browser into n sequences of instructions separated by source. We call each of those broken sequences of instructions, an Instruction Block, which has a unique URL associated with it.

We do that because our main goal is not to identify the exact same behavior between phishing websites, but to identify common patterns in the behavior. With that division, it is easier to identify similar files between phishing websites, which can be used to understand the evolution of a phishing kit. In the end, that is why calculating instruction block, is better than handling a single thread of logs.

After all the data is gathered in the Dataset, we transform the text-based representation of the logs into an embedding representation to use regular clustering techniques on top of that. The Dataset Embedding module was created to be very adaptable and can be used with DOC2VEC or SBERT techniques. In our experiments, SBERT produces less noise on the embeddings and creates embeddings that are closer to similar samples. Besides, SBERT has an attention layer that produces an importance window that is larger than the DOC2VEC approach, apart from being faster because it is based on a pre-trained model. In the end, the Dataset Embedding module embeds each Instruction Block creating a variable amount of embeddings for each sample. One can think of the result as a matrix with shape nxF, with n being the variable number of Instruction Blocks of each sample and F the number of features in the embedding technique, which is the same for all the samples. 

In the Clusterizer Module, each sample is represented by a matrix with a different number of lines, which makes it not trivial to compare the samples. In the end, we want to calculate a Representative Vector for each sample, which should be decided based on the group of embeddings calculated for that sample and then used to compare the samples among themselves. To solve that, the module was also built to be very generic, which also enabled us to try different approaches. The first one we tested was just based on the average of the lines in the matrix, which ended up creating more noise than information. Then we tried finding the most important line in the whole matrix, which would represent the file that best describes the sample, which ended up evidencing JavaScript libraries like jQuery, Bootstrap, and Popper.

Finally, we realized that, even though the number of lines was not the same in the matrix, we could perform a matrix multiplication with the transpose of the sample matrix with itself to end up with an FxF matrix for each sample, which is something that would allow us to compare the samples. The problem is that using the SBERT model, we create embeddings with 1024 dimensions, which would then create a resulting matrix with more than 1 million features for each sample. We solve that by calculating an Incremental PCA with 256 components and a batch size of 256, which was preferred due to memory limitations. Which ends up with Representative Vectors of size 256 for each sample in the dataset.

That approach calculates way more accurate clusters for similar execution traces and more or less the same number of instruction blocks. However, bigger changes in the number of instruction blocks still affect the clustering mechanisms which is reasonable based on the matrix multiplication alternative. We are still to find an alternative that completely disregards the number of instruction blocks in a sample.

Finally, the Clusterizer module uses the embeddings as the input data and accepts many different clustering algorithms, such as DBSCAN, OPTICS, and HDBSCAN. Our initial tests were made using the DBSCAN algorithm, but the final pipeline will be chosen by their performance.

All that composes the Projector module, which runs every day in parallel with the crawler. While the crawler runs every day to obtain daily new samples, the projector runs every day to use those new samples. It basically uses the samples from the days before today to build the embedding space and then uses the new samples to project them into the previously known clusters to verify which samples from today are new, and which are similar to any that were seen before. That basically allows the security analyst to understand which samples it has to manually inspect, and which are not worth inspecting.

Besides, that tool also allows us to see how the phishing kits progress over time and how long does one phishing kit remains being deployed in the wild. Also, that tool can be used to blacklist samples that have the same behavior as the ones that were already validated before.

Initial Results

Malicious Clustering Subsample Experiment

To verify if the algorithm can correctly classify different phishing samples into the same clustering, we used 249 valid samples to see the resulting clustering using their behavior. To validate the clustering we created a tool to manually inspect each cluster regarding the code that was executed, the number of blocks in each of them, and the domains requested.

Considering the clusters that had more than 1 sample in each of them, we saw mostly clusters that correctly grouped different samples with the same behavior together, which represents that the pipeline might be doing good.

Even though we had some clusters with the exact same samples, which might have been due to redirection, or failing to filter equal samples. In the end, we got interesting clusters containing slightly different execution blocks or domains, but with enough information to make us believe that the overall code structure was developed by the same author.

Reliability of the Crawler

To test if the exact same URL is equally visited by the browser and correctly assigned to the same clusters, we propose the following experiment

We selected the 10 most accessed URLs from the Alexa Top 100 index and used our crawler to visit each of them 10 times sequentially. Our hypothesis is that the clustering will result in 10 clusters with the samples in the same ones.

List of URLs:

  • https://www.google.com/
  • https://www.facebook.com/
  • https://www.youtube.com/
  • https://www.wikipedia.org/
  • https://www.amazon.com.br/
  • https://www.instagram.com/
  • https://www.linkedin.com/
  • https://www.reddit.com/
  • https://www.whatsapp.com/
  • https://openai.com/

In the end, WhatsApp, Instagram, OpenAI, Wikipedia, YouTube, and Facebook were 100% correctly grouped in the same cluster. However, Google and Linkedin were 90% correctly clustered. The samples that were clustered outside had fewer instruction blocks in it, meaning that assets were not successfully loaded during the 10s crawling or the browser was evaded. Amazon was grouped in 3 different clusters. With 10, 11-12, and 7 instruction blocks in each. While Reddit was not able to be parsed by the crawler.

After manually analyzing the sample embeddings by projecting the embeddings in a 3D space, we see that even though the samples were not assigned to the same cluster, they were not far from each other, which means that a small adjustment to the clustering algorithm would group them together. However, we would have to verify if the adjustment would not make the pipeline more prone to group different samples in the same cluster, which is equally bad.

Overall. It means that the processing tool still needs some tweaking regarding the embedding technique and clustering parameters before deploying it.

Effectiveness of the Projector


Even though it is a preliminary experiment. We run the projector on a rather small sample set from September 25th to September 29th, with September 29th as the target date to be mapped.
Overall, we used 7882 samples of old data and 1407 samples of new data. From those new points, we had 471 of them assigned to a cluster, from which 409 of them were assigned to clusters that contained old points, meaning a repeated phishing kit deployment. While we still need some tweaking on the clustering algorithm to cluster all new samples into a cluster, we identified that 86% of the phishing URLs discovered in a day were not new, but redeployment of an already known phishing kit.

Next Steps

Another experiment we would like to make is regarding progressive log files. This means understanding how the sample is located in the projection space while it is still loading. This is an experiment we still have to implement to see the results but would allow us to implement an instrumented version of Chromium that uses this approach as a blacklist for known phishing kits.

We still have a crawler that is constantly obtaining new samples which will give us insight on the distribution of phishing kits through time. However, it is something that will have to leave it running for a while before we have any conclusions about it.

Besides, we are also considering using the dynamic behavior of phishing kits to create a classification tool that will differentiate benign and malicious websites based on that behavior.



Wednesday, September 25, 2024

The Dopamine Trap: How Our Brains Process Rewards and Distractions


Processors in computers operate with an internal clock frequency, synchronizing their operations to execute instructions. Every time a computer processes tasks, energy flows through its circuits, generating heat. To manage this, processors use Dynamic Frequency Scaling, adjusting speed to balance performance and heat dissipation. This mechanism allows the processor to slow down when fewer tasks are required, reducing energy consumption and preventing overheating.

Our brains, however, seem to function differently. Instead of an internal clock, their processing speed appears to fluctuate based on the presence of hormones. When adrenaline surges—say, when escaping a wild boar (I originally considered a bear, but Leonardo DiCaprio proved otherwise)—our cognitive functions accelerate. Conversely, when lying in bed, hormone production drops, and mental activity slows. However, prolonged hormone deficiency does not seem sustainable. From an evolutionary standpoint, maintaining a baseline level of cognitive engagement is crucial for survival and progress. Perhaps this explains why our minds wander in unexpected ways, such as generating a flood of ideas during a Sunday mass. This observation also hints at why prolonged engagement with social media can feel unnatural—despite its entertainment value, something within us resists being submerged in it indefinitely. Over time, I started questioning the addictive design of these platforms and whether it’s possible to escape their grip altogether.

At its core, the desire to engage with something—anything—is what fuels our attraction to entertainment apps like YouTube. These platforms continuously offer new content to explore, preventing boredom from setting in. When boredom does strike, the brain immediately seeks the next course of action. Typically, it follows one of two paths:

  1. The Straightforward Path: This consists of well-defined tasks requiring minimal decision-making. Examples include picking up a book you’ve already started, continuing a blog post, or tackling a cybersecurity challenge. This path is appealing because it offers clear next steps. However, it also includes effortless distractions like scrolling through Instagram—an option that requires no mental effort yet provides instant gratification.

  2. The Novel Path: This involves tackling something new—such as building a physics engine in C, setting up a private DNS server, or contemplating an original idea. These tasks require initial effort just to figure out how to begin. Unlike the Straightforward Path, where progress is immediate, the Novel Path often leads to hesitation. The challenge is avoiding paralysis by over-planning—spending too much time envisioning every step rather than diving in. When a project is simple, mapping out the entire process in advance may work. But for complex endeavors, experimentation is essential. Otherwise, one risks endlessly contemplating possibilities without ever taking action, much like walking on a treadmill and expecting the scenery to change.

The difference between these two paths is clear: the Straightforward Path provides immediate clarity, while the Novel Path requires navigating uncertainty. Yet, despite its challenges, the brain seems to reward the Novel Path more generously—following a "less effort, less reward" principle. This reward system likely evolved to encourage innovation. After all, a species that only repeats familiar actions stagnates, while one that constantly explores new possibilities thrives. This explains why completing a challenging project feels profoundly more fulfilling than an hour of mindless scrolling.

Unfortunately, modern technology exploits this system by flooding the Straightforward Path with effortless, high-reward distractions. Tasks that once required effort—such as reading a book or tidying up—now compete with activities that demand almost nothing: listening to music, watching videos, or endlessly swiping through TikTok. This shift distorts the effort-to-reward ratio, making it alarmingly easy to engage in low-effort behaviors while receiving a deceptive sense of accomplishment. My biggest concern is the possibility of an entire generation growing up without ever experiencing the deep satisfaction that comes from voluntarily pursuing and completing something challenging—because their attention has been hijacked by instant gratification.

This brings me to another key factor: boredom. Boredom often serves as the gateway to Novel Path exploration. Whether sitting in church or enduring a dull lecture, these moments frequently spark new ideas. However, in our hyper-connected world, boredom is rarely tolerated. Eating a meal without watching a video, finishing a project without immediately checking notifications, or simply staring out the window until inspiration strikes—these experiences are becoming rare. Instead, the Straightforward Path takes over almost instinctively, with smartphones offering the fastest escape. While this provides immediate mental engagement, it often represents a local maximum—a temporary reward that falls short of the deeper fulfillment found through true creative exploration.

Perhaps we should give ourselves more time before reflexively reaching for our phones. But what would be the clear incentive to do so?

Tuesday, September 24, 2024

The Brain’s Resistance to Change: Why We Struggle to Shift Focus

Imagine you own a car factory with a well-oiled production line that has been running smoothly for 20 years. Your entire setup is optimized to manufacture Nissan 350Zs, and although sales are still decent, they’ve declined over time. After conducting a market study, you discover that producing Porsche 911s would significantly boost sales. The catch? Transitioning your factory to build Porsches would require a complete overhaul of the production line. On top of that, a voice in your head whispers, “Why change something that’s still working?”—a sentiment that makes the decision even harder.

This dilemma isn’t limited to car manufacturing. This morning, over breakfast, I realized that I’ve experienced a similar internal struggle in an entirely different context. A while ago, I was experimenting with video editing techniques and truly enjoying the process. At some point, I told myself that I should stop and switch to another task. Surprisingly, this turned out to be the most challenging part of the day. It felt as if my brain was resisting the change with all its might. Even though I logically knew it was time to move on, my brain kept flooding itself with chemicals designed to keep me focused on what I was already doing.

Not being a neurologist, I started thinking of an analogy: the brain might function like the flow of a river. Picture a river—every water droplet is moving in the same direction, with a steady speed, which only changes gradually over time. If you suddenly try to redirect the flow, the entire mass of water resists, naturally trying to maintain its course. Similarly, when you're deeply engaged in an activity, your brain has directed its energy and resources to the neurons that best support that task. Changing direction requires a full-scale reconfiguration of hormones and neural pathways, which is why it feels so difficult.

This concept might also explain why social media and entertainment apps are so addictive. If you’re fully immersed in a difficult math problem, resisting distractions like TikTok is relatively easy—the ‘river’ is already flowing in the direction of deep concentration. However, if you open your phone first thing in the morning, when no strong cognitive direction is established, it’s easy to fall into a scrolling loop. Once engaged, your brain’s ‘Entertainment Neurons’ take control, and shifting focus to something demanding becomes a battle against inertia. Even if you force yourself to start a productive task—say, working on an assignment—your brain might still be drawn to the dopamine rush of social media, making concentration difficult.

What concerns me most is how our habits shape the brain over time. Repeated exposure to social media strengthens neural pathways associated with instant gratification, while reducing the volume of mental resources allocated to deep thinking and problem-solving. It’s frightening to consider that my fingers have memorized the exact motion required to open Instagram, as if on autopilot. While social media certainly has its benefits—improving communication and socialization—it’s alarming that something as mindless as clicking an app has become so reflexive.

Moreover, I’ve noticed that excessive use of entertainment apps diminishes my ability to ponder big questions—questions about life, society, and existence itself. Deep thinking requires an uninterrupted mental state, something that modern distractions constantly threaten. Yet, at the same time, completely avoiding social media might come at a cost—potentially hindering my ability to connect with others.

So, what’s the solution? Balancing focus, entertainment, and deep thinking feels like a million-dollar question—one that we all must grapple with in an era of endless digital distractions.

Monday, August 26, 2024

[Rephrasing] PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing Blacklists

 💡This is a reader's perspective on the paper written by Adam Oest (from Arizona State University) and published at the USENIX Security Symposium 2020.

Brief Description

The authors provide a study to obtain a perspective on the operation of phishing blacklisting tools (such as Google Safe Browsing and Microsoft SmartScreen). To do that, they automatically launch more than 2,000 phishing websites, each with different cloaking techniques to understand which of them is detected and how long it takes.

[Rephrasing] Sunrise to Sunset: Analyzing the End-to-end Life Cycle and Effectiveness of Phishing Attacks at Scale

💡This is a reader's perspective on the paper written by Adam Oest (from Arizona State University) and published at the USENIX Security Symposium 2020.

Brief Description

The authors seek to understand the timespan between the development of the phishing kit, the distribution, and the discovery of the phishing websites. They do that by analyzing the requests made by the phishing website to the benign website to request images and stylesheets. Using that, they find out that phishing webpages have on average 21 hours to abuse users until they are discovered by defenders.

Observations

I like the idea of providing an experiment that reduces the "Golden Hour duration", that is a term they claimed and is worth being the creators. However, there should be an easier metric to calculate the Golden Hour duration for phishing websites that target a specific brand, which there isn't considering it is required to have access to private information from the company to calculate that.

Another interesting experiment was to track the effectiveness of phishing emails by the reports that users do to the company. However, this is not related to the users who fall for the phishing attack because those are the ones who would not report the website. I need to check the study "Cognitive triaging of phishing attacks" before questioning if that is a research GAP.

I would also like to know what is the "public dump" they mention in Section 4.1, because that would be interesting to check. I wonder if that is a private repository from the company itself.

One last question I had was about the pros of using an asset served by the benign webpage. Is it to bypass detection metrics? Or is it just laziness from the attackers?

Initial Questions

The first question I had was regarding the user network traffic of phishing web pages. They mention that they do that by accessing private information from a specific company in the financial sector, which is not reproducible by future work, but it is a nice idea to take advantage of.

Where do the experiment ideas come from?

They mention that "Cognitive triaging of phishing attacks" uses a similar approach to understand the effectiveness of phishing email lures. That might be the main motivation behind the ideas.

What are the interesting ideas/results?

The first genius idea is to leverage requests to benign content as a tracker for phishing websites. That is a thing I have never seen before.

Nice preliminary study in Section 3.2 to understand that phishing pages usually request content from benign pages.

In Section 4.3, a nice confirmation of a metric visualized in the data with a report from APWG Q3 2019.

Nice geolocation experiment in Section 5.1 to verify the time at which the phishing page was being developed.

Sunday, August 25, 2024

[Rephrasing] Discovering HTTPSified Phishing Websites Using the TLS Certificates Footprints

💡This is a reader's perspective on the paper written by Yuji Sakurai (from Waseda University) and published at the IEEE European Symposium on Security and Privacy 2020.

Brief Description

This paper proposes a series of studies on HTTPs used for phishing. They propose a way to collect data, a clustering technique, and a classification algorithm based on TLS-based information, mainly the domain of the phishing website, that uses regex to find interesting patterns in the phishing domain.

Observations

Even though I was a bit skeptical about the idea of using the domain name to cluster the dataset, they proposed an interesting approach using regex (which might be an influence from one of the coauthors, very strange approach if otherwise), which is worth reading.

One other question I had was regarding the hyper-parameter testing on the DBSCAN. They should've tried changing the default parameters since they just stated that this was the only thing they tried.

Initial Questions

My first question was if they were proposing a classification for phishing websites. In the end, they do propose an unsupervised "classification" system that is based on their dataset.

Where do the experiment ideas come from?

Since there were already other tools that used TLS information to classify malicious URLs, I suspect that the idea was to improve the existing tools.

What are the interesting ideas/results?

I like the LCS-based algorithm to calculate the difference of strings.

I really like the example they provided in Section 3.3 to explain their algorithm.

Nice confirmation that Lets Encrypt is highly used by phishing websites, which was explored in other papers as well.

[Rephrasing] Security Analysis on Practices of Certificate Authorities in the HTTPS Phishing Ecosystem

 💡This is a reader's perspective on the paper written by Doowon Kim (from the University of Tennessee, Knoxville) and published at the ACM ASIA Conference on Computer and Communications Security 2021.

Brief Description

The authors provide a nice view of the role of certificate authorities in the phishing landscape. They first study how they validate the website to emit certificates, the effectiveness of HTTPS Phishing websites, and the procedures of CAs for emitting and revoking certificates. Also, they mention how they treat reports for phishing websites. 

Observations

In Section 1, they mention that of all successful phishing attacks (I also have no idea how they consider one to be successful), 85% are HTTPs Phishing, and the other 15% are HTTP Phishing. That success rate might not mean much if the amount of HTTPS Phishing attacks is also 85%. Later they mention that the amount of HTTPs Phishing is closer to 86%, which basically means that it is worse, isn't it?

Second, why is it good for the CAs to emit certificates to phishing websites? Is it related to the number of emitted phishing websites (That could later increase the evaluation of the company)? Or is it about the price required to evaluate each website for which you are generating the certificate further? It could be a further research GAP.

Another thing I don't agree with the authors is related to the removal of the password field in the Mock Phishing websites. They mention it to be an ethical thing to avoid making regular users to input their information, but they could do it by not storing the information that users put in. If you remove the password field, it will not try to steal the user's password, which would make it different than a phishing website.

Initial Questions

The first thing I asked myself was regarding their URL data source, and whether the phishing websites were required to be live. While I don't know the answer to the second question, they mentioned later that they got those URLs from APWG eCX.

Where do the experiment ideas come from?

I suspect that the inspiration for the paper is based on the curiosity of how malicious websites could be verified, and how the "false" security that Chrome imposes might hurt the users.

What are the interesting ideas/results?

I really like the sequence of experiments on the evaluation of certificate authorities.

Nice idea on the deployment of phishing websites to verify the behavior of CAs

Saturday, August 24, 2024

[Rephrasing] Catching Transparent Phish: Analyzing and Detecting MITM Phishing Toolkits

💡This is a reader's perspective on the paper written by Brian Kondracki (from Stony Brook University) and published at the ACM Conference on Computer and Communications Security 2021.

Brief Description

That is a nice paper that analyses features related to RTT and TLS information from certain Reverse-Proxy MiTM phishing kits, to create a classification tool for webpages built with those phishing kits. They use that to verify how many web pages are being deployed in the wild with those phishing kits.

Observations

One thing they mention is the idea of an "all-in-one phishing toolkit", that redirects the regular pages from benign websites to phishing victims. I would like to see a concrete example of that since I have never seen such an example.

I was thinking that this 2FA at least mitigates the sharing/selling of passwords from a single website, since you can only share the authentication token (which can be bonded to the IP address). I wonder if there is a possibility to bind the cookie to the MAC address of the computer for further protection (Maybe a solution provided by the browser).

I wonder what hacker forums they are talking about in Section 3.1.

They mention that one of the features they use for the classification system is RTT. That is the beginning of a performance-based classification of phishing kits (Which is still a huge study GAP).

Problem in Section 4.1 (forgot to reference the table).

I would like to see the number of blank windows from their headless crawler (They don't mention it).

They use brand impersonation using only the URL from the website, which could add to the idea of brand detection using content-based features.

Initial Questions

When reading the abstract, I wondered what framework they used for crawling in new URLs, and if they were possibly evaded by cloaking techniques. They mention that they are using a regular Selenium version in headless mode, which seems that they are possibly being evaded.

One other thing that I was thinking was related to the tool they used to collect network-related information. I guess I did not get the answer to this directly in the paper, but I suggest that they are using features from selenium to capture that kind of information.

Lastly, I wondered what were their sources for URLs, which they mentioned to be PhishTank and OpenPhish. (Which might open a GAP to research on certificate-based URL publishing, such as CertStream).

Where do the experiment ideas come from?

I guess that it mostly came after accessing those open-sourced MiTM phishing toolkits from GitHub.

What are the interesting ideas/results?

Nice briefing on advanced cloaking techniques in Section 3.2.

Nice tool TLSProber.

Nice robustness testing on the Random Forest classifier in Section 3.5.

Nice experiment on the difference of domains in Section 4.2.

Friday, August 23, 2024

[Rephrasing] Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO Protocols

💡This is a reader's perspective on the paper written by Enis Ulqinaku (from the Department of Computer Science, ETH Zürich) and published at the USENIX Security Symposium 2021.

Brief Description

The authors propose a different attack perspective on the FIDO authentication mechanism. Since most websites have other account verification techniques, besides FIDO, the authors thought of faking the FIDO verification dialog prompting the user for an OTP number and faking the FIDO authentication in the benign websites. Unfortunately, it was only a preliminary study on the topic, since they were unable to provide any information on whether the users really fell for that attack since most had already identified the websites as phishing from the email message or the website characteristics (URL/content).

Observations

One very strange thing is that they claim that FIDO is the solution for MITM phishing attacks, but I don't see how that is. I see it just as another OTP-like verification system.

In all, I think that a user study regarding this topic is still a very large study GAP since it was hard to really evaluate that attack's effectiveness.

I also don't like that they do not implement any crawler to interact with the benign page, even as a POC. From my point of view, the correct interaction with the benign webpage is as important as making the user believe in the full process

Initial Questions

The first question I had on the paper was about the crawler they used on benign pages to correctly interact with them. But they didn't any, since they claimed it was an only "user study", so meh...

Where do the experiment ideas come from?

Might have come from an insight on the studies. While the methodology in the paper is nice, they could've focused on other important things, such as making a full POC.

What are the interesting ideas/results?

Nice methodology for the user study. Very detailed

Thursday, August 22, 2024

[Rephrasing] Catching Phishers By Their Bait: Investigating the Dutch Phishing Landscape through Phishing Kit Detection

💡This is a reader's perspective on the paper written by Hugo Bijmans (from the Netherlands Organisation for Applied Scientific Research) and published at the USENIX Security Symposium 2021.

Brief Description

The authors propose a way of categorizing phishing kits and checking how are they being used in the wild. To do that, they propose a graph-based community identification of phishing kits by source code similarity and observe CertStream URLs to crawl for certain fingerprints identified on each phishing kit in their dataset.

Observations

GAP: Study on brand impersonation and phishing kit detection. Which are the more common impersonated brands. Are there phishing kits with different brand impersonations?

The only sources of phishing kits they studied were Telegram and PhishFinder-like tools. There is room for improvement on websites such as phishunt.io or private datasets.

Another interesting idea is to compare the clustering of the phishing kits or logo identification with the favicons of the website. I still wonder how many phishing webpages do not have a favicon, or a favicon not related to the brand impersonation.

I like the heuristic approach to finding URLs in CertStream. But they could use an existing phishing detection tool for that.

One drawback of this approach is that you have to identify the phishing kit source code to identify it in the wild.

Initial Questions

One of the main problems I face in code comparison of phishing websites is Code Obfuscation. Therefore I asked myself if they handled that somehow to compare the phishing kits with the live webpages. In the end, they use specific path/string-based fingerprints in certain files to identify what phishing kit is being used.

Where do the experiment ideas come from?

I think it might have come from the moment they accessed free phishing kits from Telegram groups.

What are the interesting ideas/results?

Nice time explanation of the experiments in Section 3.4.

Nice experiment with evasion techniques used in phishing kits. That may lead to some other very interesting experiments.

Nice explanation in Section 7 on features of phishing pages that do appear on PhishTank vs phishing pages that do not even get there (might be more complex ones).

[Rephrasing] Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing Webpages

💡This is a reader's perspective on the paper written by Yun Lin and Ruofan Liu (from the National University of Singapore) and published at the USENIX Security Symposium 2021.

Brief Description

This is a proposition of a system that identifies what brand is being impersonated by the phishing webpage, given a training set of benign logos. The tool proposes a deep-learning algorithm to identify where on the page is the logo, and if the logo is similar to one of the training sets.

Observations

One thing that is very clear to me, every time I read a paper from those authors, is how short is my knowledge of deep learning algorithms. This should be fixed, because I could understand almost nothing of Section 3.2 on the explanation of the requirement of using Resnetv2 as a preliminary classification network).

In Section 5.1, I don't understand how they manually analyzed 350K phishing URLs and how "sometimes" they corrected the labels collected from OpenPhish. Similarly, in Section 5.2.1 they also mention the manual validation of 5,000 web pages.

Initial Questions

At first, I wanted to know where the benign logo dataset came from. Later the authors mention the usage of Logo2K+, which is commonly used by the authors in future work as well.

Where do the experiment ideas come from?

The authors seem to be very familiar with deep learning algorithms, so that might be their main motivation for this kind of work.

What are the interesting ideas/results?

In Section 3.2, I like the catch on the necessity of using a Siamese model to perform logo identification. This is caused by the drawback of multi-label classification systems (they will always classify as one of the trained labels).

Nice explanation on the required Step ReLU to harden adversarial attacks.

I like the log scale in Figure 10 to portray the advantages of the Phishpedia classification ROC curve.

Nice qualitative analysis from both the Phishpedia tool and the baseline tools. (Nice section "Why does Phishpedia outperform the baselines)

Wednesday, August 21, 2024

[Rephrasing] Assessing Browser-level Defense against IDN-based Phishing

💡This is a reader's perspective on the paper written by Hang Hu (from the University of Illinois at Urbana-Champaign) and published at the USENIX Security Symposium 2021.

Brief Description

This paper provides a huge study on IDNs (Internationalized Domain Names), which are domains not written fully in ASCII. Since Unicode groups different languages, there are languages with different Unicode but similar at the same time. This proposes a deep study on how the browser handles those IDNs, what are the perception of the user on IDNs, and how social media and email providers handle those IDNs.

Observations

While I like the study on mobile browser behaviors on IDNs, studying the user perspective on phishing domains on mobile browsers is still a research GAP (One might use the automatic infrastructure they used in this paper to test it, with LambdaTest).

One thing that I am still aiming to find out is the skeleton rule classification system they created. I wonder if it does involve any image processing behind the scenes ( Section 4.1).

This paper should also propose a protocol to be followed by most browsers to avoid causing that result difference between the browsers when interpreting the domains.

In Section 5.2 they mention that Chrome fails to enforce the rules they claimed. I still wonder if it was an experiment error thing (while Google might have plenty of automatic testing tools to enforce it).

The paper mentions some studies regarding phishing, but I still did not see anything regarding those domains phishing-wise. Plenty to explore.

Initial Questions

At first, I asked myself about the way they found 1,855 homograph IDNs in a set of 900,000. But they essentially develop an algorithm to do that automatically. That leads to some of the disagreements I have regarding the "effectiveness" of Chromium in detecting homograph IDN. It is not the case that Chrome is bad, it is just that the algorithm is different, in which case the Google developers might have decided how close it should be to be considered "homographic", in which case the False Negatives might not really be False Negatives. In this sense, I personally found most of the False Negatives very different from the real domains, such that a regular user might find out that something is wrong.

Where do the experiment ideas come from?

At first, I had no idea where the idea of studying IDNs came from. But they might have got it from the eCrime paper written in 2018 called "Large scale detection of IDN domain name masquerading". Nice inspiration on the experiments to further explore this area of work.

What are the interesting ideas/results?

Nice testing with already existing datasets.

Nice "category" creation for the experiments. Made it much more clear.

Nice usage of Google Tesseract to perform character recognition.

Verifying network traffic/Source code verification is nice to understand the behavior.

Time-series studies are always amazing.

Nice to mention the testing plan for user studies.

Tuesday, August 20, 2024

[Rephrasing] I’m Spartacus, No, I’m Spartacus: Proactively Protecting Users from Phishing by Intentionally Triggering Cloaking Behavior

💡This is a reader's perspective on the paper written by Penghui Zhang (from Arizona State University) and published at the ACM Conference on Computer and Communications Security 2022.

Brief Description

The authors propose a tool that abuses the cloaking techniques that phishing websites use to protect users against them. The idea is that if crawlers can't see the phishing page, then users will not as well. They also evaluate a lot of server-side cloaking abused by phishing websites regarding how are they used in the wild. In the end, they evaluate how benign pages are affected by that.

Observations

I don't understand the idea of using a blacklist of  URLs to enhance the tool. Is it because only the behavior analysis was not enough or was it to enhance the time performance of the tool in malicious websites?

Another idea I had while reading the paper was to try to mimic some other type of client-side fingerprinting. Which is a huge study GAP I want to explore later, as a tool to systematically modify fingerprinting inputs.

In Section 4.4 they mention that uncloaked websites take 28 minutes to be detected. But is it 28 minutes starting from when?

In Section 5 they mention the hashing of the URLs to store it for future usage, however, I am not sure if it is a good option since it is easy to create a different hash from the same domain using a simple unused query parameter.

Initial Questions

One thing that I had in mind was, how did they intercept the network connections to rewrite the HTTP header parameters? While they do not mention specifically that, they expose that their tool is a browser extension, and there are a lot of extensions that modify HTTP requests. Therefore, it might be possible in that way. (Btw, never done anything like that. What an interesting thing to try).

Where do the experiment ideas come from?

All the ideas of the paper are around the crawler-imitating idea. After that, they create the extension and think about the experiments.

What are the interesting ideas/results?

Nice idea on the impact on benign websites. Besides that there are a lot of experiments around that, for example, verifying a large group of URLs from Alexa Top 1M, manually verifying the results in a smaller dataset, using the extension for a month as a regular user, and verifying the impact of 2FA on the tool.

I like the modularization of the tool into "profiles" that can be modified and tested separately in the experiments section.

In the disclaimer section, I like the attention given to the usage of user data.

Finally, I really like the deep analysis of the False Positives in Section 6.6 as it gave a lot of insights into the behavior of the tool.


[Rephrasing] Clues in Tweets: Twitter-Guided Discovery and Analysis of SMS Spam

💡This is a reader's perspective on the paper written by Siyuan Tang (from Indiana University Bloomington) and published at the ACM Conference on Computer and Communications Security 2022.

Brief Description

The authors propose a method to collect spam messages from the Twitter feed. By searching for blacklisted words such as "scam" or "phish" they collect a database of phishing messages, which are later classified using ML as actually a Scam or not. Later, the authors explore the Scam detection systems already created and propose insights into how the Scams work.

Observations

The first thing that I had in mind was a tool to classify it. Since they do not propose it, I suppose that it is still a research GAP to be explored by researchers.

Something that I would like to know is regarding brands in the study. They mention that collect a huge data on Scams, but I still want to know what is the company that is mostly faked by those scams. Ig it is still a research GAP.

Initial Questions

The very first question I had was regarding the data collection mechanism, which they claim to use the Twitter Academic API for.

Where do the experiment ideas come from?

All the paper runs around the idea of collecting Scam messages from Twitter on a large scale. All the following experiments provide insights about the data, and the tools are made to correctly collect and evaluate the data.

What are the interesting ideas/results?

The first interesting idea from the paper is the ability to search for information using social media. Other social media such as Facebook and Reddit were also explored, but I wonder how it can be used for phishing searching (since it might appear much earlier than platforms like VirusTotal or PhishTank).

I like the exploration of the different languages in the dataset, even though it is a preliminary study on the topic (Maybe can be used for phishing as well).

Also, they used Google Vision to extract text from images, which is a very nice approach. In the same way, another interesting tool is the Twilio Lookup API to search for phone number information.

One other interesting idea they had was to evaluate in a time-series manner the Scam landscape. They explored slightly but could be even more exhausted.

They also verify network information such as IP information and DNS datasets to collect further insights on the URLs shared by the Scam messages.


[Rephrasing] Phishing URL Detection: A Network-based Approach Robust to Evasion

💡This is a reader's perspective on the paper written by Taeri Kim (from Hanyang University) and published at the ACM Conference on Computer and Communications Security 2022.

Brief Description

First of all, this paper is highly mathematical and I don't have (and did not have the intention to have) the knowledge required to make propositions and contributions to the content. Besides that, I also skipped some [what might have been] very important parts, because reading it or not had the same result (As I didn't intend to spend the time to fully understand it).

Besides that, the authors provide a URL-based classification using network theory by splitting the URLs into separate words to better associate the words with phishing-related features, such as their IP addresses. They also mention that URL-based detection is worth studying because it can be used as a first-barrier classification that does not need to access the content of the phishing pages, which can be masked by cloaking techniques (Reasonable).

Observations

I understand that this paper is a plate full of food for a person who is into network theory, but I wonder if there wasn't any better way of explaining it with examples.

One thing that I recognize here is that I really need to understand deep learning better and get into the TensorFlow framework.

Initial Questions

The first question I had was on Section 2.2, which I wondered what are the brands that are mostly targeted. While I didn't find the answer to this in this paper, I think that it might be a nice experiment GAP to be done in future research.

Where do the experiment ideas come from?

I suppose that one of the authors of the paper is very into network theory, and they had a student who really likes computer security and found URL-based classification as a great mix. Besides, they had a lot of creativity to test the model on (even though it might not have been the most creative I have ever read).

What are the interesting ideas/results?

I like the way they say that PhishTank is not reliable because it can be messed up by attackers. Even though it is possible to do this automatically, I wonder how great this problem is. However, I like the idea of verifying the set of URLs in VirusTotal to further explore it.

I also like the idea of testing different methods as a comparison experiment to test if the data collection system is robust, which they did in Section 6.2.

Finally, I like the time complexity calculation to explore the network model that they explored further. Besides that, I like the explanation for the transductive approach they took.



Monday, August 19, 2024

[Rephrasing] Leaky Forms: A Study of Email and Password Exfiltration Before Form Submission

 💡This is a reader's perspective on the paper written by Asuman Senol (from the University in Leuven) and published at the USENIX Security Symposium 2022.

Brief Description

The main idea behind the paper is that identify what the webpages do with the user credentials once they start typing them on the page forms. They do that by leveraging the DuckduckGo Tracker Radar Collectors which uses Chrome Devtools Protocol and a Network tracer to identify how the information is being sent do the server. While they focus only on the information sent to the tracker domains, they solve the challenge of encoded information by calculating many encodings beforehand and comparing that to the information sent through HTTP and Websockets 

Observations

Verifying if phishing websites also have this behavior of collecting stuff while it is being typed is a very nice idea and seems to be an open research GAP.

This paper also uses the Chrome DevTools Protocol (CDP) to capture the behavior of the webpage, which might be a good thing to try.

In Section 3.2 they mention that use the position of the buttons in the page to find out how the crawler can go to login pages. Even though it might seem to be a good idea, I can't figure out if the effort of making that tool is really usable.

I don't like the idea of restricting the capturing of the behavior only from tracker domains, I would like to see a perspective on benign domains as well, even if it might be a separate study.

One interesting topic is the idea that trackers behave differently based on user geolocation because some just collect information from clients that are in the US. I guess that it is still a research GAP to understand if phishing also has a different behavior from users in different locations.

Besides that, identifying if the behavior of phishing websites is different in mobile vs desktop environments is a nice research GAP, and might be interesting to find out.

Initial Questions

The first thing that popped into my mind was about the tool they use to collect those behaviors, which became clear through the description of the methodology.

Where do the experiment ideas come from?

I am a little in doubt about the beginning of the study, whether it was related to a motivation study published by Surya Mattu, or if it was related to the idea of using the DuckduckGo tool

What are the interesting ideas/results?

The attention to the GDPR rules is a very nice idea for experiments. Sending the requests and giving a description of the GDPR scope in this paper is a very nice result for the reader.

They use a tool called Mozilla Fathom, which identifies different parts of the page automatically (as a classifier?). Very interesting idea to identify email and password fields.

Another idea they had was related to the "Do you allow cookies" pop-up. On some pages, even with the user clicking on "No tracking", they still collect the information. Besides that, it is interesting to see some scenarios where the user still receives emails from webpages that secretly collect their emails.