SBIR-STTR Award

Robust and Efficient Anti-Phishing Techniques
Award last edited on: 2/1/2013

Sponsored Program
SBIR
Awarding Agency
DOD : OSD
Total Award Amount
$848,458
Award Phase
2
Solicitation Topic Code
OSD10-IA3
Principal Investigator
Kurt Wescoe

Company Information

Wombat Security Technologies

4620 Henry Street Third Floor
Pittsburgh, PA 15213
   (412) 621-1484
   info@wombatsecurity.com
   www.wombatsecurity.com
Location: Single
Congr. District: 12
County: Allegheny

Phase I

Contract Number: ----------
Start Date: ----    Completed: ----
Phase I year
2011
Phase I Amount
$99,206
Phishing attacks fool end-users into disclosing sensitive information (e.g., passwords, trade secrets, and national security secrets) or installing malware on their computers. While a number of automated solutions have been developed to mitigate these attacks, these solutions have drawbacks in terms of scalability, timeliness, and accuracy. Our goal is to develop novel anti-phishing email and web filtering techniques that overcome these limitations and dramatically improve the state of the art. Our work will combine two new technologies originally developed at Carnegie Mellon University, as well as novel linguistic analysis techniques. These technologies will make it possible to deploy email and web filtering solutions that exhibit considerably higher levels of accuracy than today’s solutions in a manner that is highly scalable and effective against zero-hour attacks. We have three key objectives for this Phase I effort: (1) evaluating system architectures that integrate our existing anti-phishing technologies in a way that is highly accurate, timely, and scalable both for the web and for email; (2) developing and evaluating natural language processing techniques that detect both spear-phishing and “reply-to” emails; (3) refining go-to-market strategies for these filters, in terms of deployment options and business models.

Keywords:
Phishing, Email Filter, Web Filter, Natural Language Processing, Machine Learning, Information Assurance, Computer Security

Phase II

Contract Number: ----------
Start Date: ----    Completed: ----
Phase II year
2012
Phase II Amount
$749,252
Phishing fools end-users into disclosing sensitive information or downloading malware. Commercially available solutions have shown limited success in stopping these attacks. We aim to refine and commercialize novel anti-phishing email and web filtering techniques that overcome these limitations. Our approach combines two new technologies originally developed at CMU, as well as novel linguistic analysis techniques. In Phase I, we showed that these technologies can achieve significantly higher levels of accuracy than today’s solutions and are both highly scalable and effective against zero-hour attacks. In Phase II, we will refine and extend these techniques and make them available in configurations that are compatible with those typically found in both private sector and government settings (including DoD).

Keywords:
Phishing, Email Filter, Web Filter, Zero-Hour Attack, Machine Learning