首页> 外文会议>International Conference on Natural Computation, Fuzzy Systems and Knowledge Discovery >Email trouble: Secrets of spoofing, the dangers of social engineering, and how we can help
【24h】

Email trouble: Secrets of spoofing, the dangers of social engineering, and how we can help

机译:电子邮件问题:欺骗的秘密,社会工程的危险以及我们如何提供帮助

获取原文

摘要

Email spoofing is a method of scamming individuals by impersonating a trusted correspondent via email. Incidences of successful Business Email Compromise (BEC) implemented by email spoofing are rising astronomically. Existing security systems are not widely implemented and cannot provide perfect protection against a technological threat that relies on social engineering for success. When existing security systems are implemented the settings are generally not restrictive enough to catch the more sophisticated email attacks. Businesses are not comfortable with legitimate emails being lost due to security false positives. Our idea for a solution would add a layer to existing precautions that would permit looser server-side security settings but would warn the user when discrepancies occur in the header source code that could result from a spoofed email. We suggest a client-side sentinel to vet email header source code and alert the user to potential problems. This software could log alerts, notify company officials, remind users of company policies to be followed in the event of suspicious email, and could increase user accountability by logging incidents. Users could have the option of white-listing frequently flagged trusted correspondents which would decrease the annoyance of false positives.
机译:电子邮件欺骗是一种通过电子邮件冒充受信任的通讯员来欺骗个人的方法。通过电子邮件欺骗实现的成功的“企业电子邮件妥协”(BEC)的发生率正在急剧上升。现有的安全系统并未得到广泛实施,并且无法针对依靠社会工程取得成功的技术威胁提供完善的保护。当实施现有的安全系统时,设置通常没有足够的限制以捕获更复杂的电子邮件攻击。企业对因安全误报而丢失合法电子邮件感到不满意。我们对解决方案的想法是在现有预防措施的基础上增加一层,以允许进行较宽松的服务器端安全性设置,但会在用户头源代码中出现由欺骗性电子邮件引起的差异时向用户发出警告。我们建议使用客户端哨兵审核电子邮件标头的源代码,并提醒用户潜在的问题。该软件可以记录警报,通知公司官员,在发生可疑电子邮件时提醒用户要遵循的公司政策,并可以通过记录事件来增强用户的责任感。用户可以选择将频繁标记的受信任通讯者列入白名单,这将减少误报的困扰。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号