Home / Companies / Elastic / Blog / Post Details
Content Deep Dive

Detecting phishing with computer vision: Part 2, SpeedGrapher

Blog post from Elastic

Post Details
Company
Date Published
Author
Bill Finlayson • Daniel Grant
Word Count
2,791
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

SpeedGrapher is a computer vision tool developed to detect macro-enabled document-based phishing attacks, a prevalent form of phishing where victims are tricked into opening malware-embedded documents. Unlike Blazar, which targets homoglyph attacks, SpeedGrapher focuses on identifying malicious documents by analyzing visual cues such as prominent colors, blur detection, blank detection, optical character recognition, and icon detection using technologies like K-means clustering, YOLOv3, and OCR. The tool generates feature vectors from these analyses, which are then used to train a Random Forest classifier for predicting the likelihood of phishing in new samples. The initial model for SpeedGrapher demonstrates a high level of accuracy, with a respectable area under the ROC curve of 0.98, and highlights the potential of computer vision in enhancing security measures against evolving phishing tactics. As the development continues, the tool aims to incorporate additional features and file types to better protect users from sophisticated phishing threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Serverless 1 286 31 18 -9%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.