首页> 外文会议>European Conference on Cyber Warfare and Security >Improving Phishing Awareness in the United States Department of Defense
【24h】

Improving Phishing Awareness in the United States Department of Defense

机译:提高美国国防部的网络钓鱼意识

获取原文

摘要

Phishing emails are rapidly increasing in sophistication, evolving from poorly crafted attempts to entice a recipient to click, into legitimate looking emails and attachments. In response, email providers have to improve their detection technology by adding new rules to their firewalls and filters to block incoming spam and phishing emails. To overcome technical measures, attackers modify the content of their phishing emails and the source email address. In this cat and mouse game, network defenders rely on the user to report new threats, and the users depend on phishing awareness training to help them identify malicious emails. For a large organization like the United States DoD (DoD) which boasts a workforce of 3.2 million employees, it is difficult to properly train employees to identify and report malicious emails. Like other organizations the DoD requires its employees to complete phishing awareness training, however the effectiveness of this training is widely disputed. Phishing prevention can be broken into three main components: automated filters and firewalls, automated warning messages, and behavioral training. This paper analyzes existing United States DoD phishing awareness behavioral training and proposes 3 principles of an improved behavioral training model. This paper will detail how focused training objectives, a DoD content-sharing platform and a realistic delivery method can be combined to offer an effective and sustainable phishing awareness campaign.
机译:网络钓鱼电子邮件迅速增加复杂,从制作不良的尝试中诱使收件人点击,进入合法的电子邮件和附件。作为响应,电子邮件提供商必须通过将新规则添加到防火墙和过滤器来阻止传入的垃圾邮件和网络钓鱼电子邮件来提高其检测技术。为了克服技术措施,攻击者修改网络钓鱼电子邮件的内容和源电子邮件地址。在这只猫和鼠标游戏中,网络捍卫者依靠用户报告新的威胁,用户依赖于网络钓鱼的意识培训,帮助他们识别恶意电子邮件。对于像美国国防部(国防部)这样的大型组织,拥有320万员工的员工,很难妥善培训员工识别和报告恶意电子邮件。像其他组织一样,国防部要求其员工完成网络钓鱼意识培训,但这项培训的有效性是广泛的争议。网络钓鱼预防可以分为三个主要组成部分:自动化过滤器和防火墙,自动警告消息和行为培训。本文分析了美国国防部网络培养意识行为培训,并提出了3种改进行为培训模型的原则。本文将详细介绍如何聚焦培训目标,国防部内容共享平台和逼真的交付方法,以提供有效和可持续的网络钓鱼意识运动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号