Company
Date Published
Author
Bill Finlayson • Daniel Grant
Word count
2791
Language
English
Hacker News points
None

Summary

SpeedGrapher is a computer vision tool developed to detect macro-enabled document-based phishing attacks, a prevalent form of phishing where victims are tricked into opening malware-embedded documents. Unlike Blazar, which targets homoglyph attacks, SpeedGrapher focuses on identifying malicious documents by analyzing visual cues such as prominent colors, blur detection, blank detection, optical character recognition, and icon detection using technologies like K-means clustering, YOLOv3, and OCR. The tool generates feature vectors from these analyses, which are then used to train a Random Forest classifier for predicting the likelihood of phishing in new samples. The initial model for SpeedGrapher demonstrates a high level of accuracy, with a respectable area under the ROC curve of 0.98, and highlights the potential of computer vision in enhancing security measures against evolving phishing tactics. As the development continues, the tool aims to incorporate additional features and file types to better protect users from sophisticated phishing threats.