首页> 外文会议>IEEE European Symposium on Security and Privacy Workshops >No Phishing With the Wrong Bait: Reducing the Phishing Risk by Address Separation
【24h】

No Phishing With the Wrong Bait: Reducing the Phishing Risk by Address Separation

机译:不使用诱饵进行网络钓鱼:通过地址分离降低网络钓鱼风险

获取原文

摘要

Email-based phishing is still a widespread problem, that affects many users worldwide. Although many aspects of phishing have been extensively studied in the past, they mainly focus on the execution and prevention of different types of phishing and do not consider the process how attackers collect the contact information of potential victims. In this paper, we analyze the collection process of email addresses in more detail. Based on the results of this analysis, we propose email address separation as a way for users to detect phishing emails, and reason about its effectiveness against several typical types of phishing attacks. We find, that email address separation has the potential to greatly reduce the perceived authenticity of general phishing emails, that target a large amount of users, e.g., by impersonating a popular service and spreading malware or links to phishing websites. It is, however, not likely to prevent more sophisticated phishing attacks, that do not depend on the impersonation of a previously known organization or entity. Our results motivate further studies to analyze the usability and applicability of the proposed method, and to determine, whether address separation has additional positive effects on users’ phishing awareness or automated phishing detection.
机译:基于电子邮件的网络钓鱼仍然是一个广泛的问题,影响全球许多用户。虽然过去的网络钓鱼的许多方面已经过广泛研究,但它们主要关注执行和预防不同类型的网络钓鱼,并且不考虑攻击者如何收集潜在受害者的联系信息的过程。在本文中,我们更详细地分析了电子邮件地址的收集过程。根据该分析的结果,我们提出了电子邮件地址分离,作为用户检测网络钓鱼电子邮件的一种方式,以及对其对几种典型类型的网络钓鱼攻击有效性的原因。我们发现,电子邮件地址分离有可能大大减少通用网络钓鱼电子邮件的感知真实性,这些电子邮件是大量用户,例如,通过模拟流行的服务和扩展恶意软件或与网络钓鱼网站的链接来实现大量用户。然而,它不太可能防止更复杂的网络钓鱼攻击,这不依赖于先前已知的组织或实体的模拟。我们的结果有助于进一步的研究来分析所提出的方法的可用性和适用性,并确定地址分离是否对用户的网络钓鱼意识或自动网络钓鱼检测具有额外的积极影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号