首页> 外文期刊>Information Security, IET >Detecting lateral spear phishing attacks in organisations
【24h】

Detecting lateral spear phishing attacks in organisations

机译:检测组织中的横向鱼叉式网络钓鱼攻击

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Lateral spear phishing attack is a powerful type of social engineering attack carried out using compromised email account(s) within the target organisation. Spear phishing attacks are difficult to detect due to the nature of these attacks. The inclusion of a lateral attack vector makes detection more challenging. The authors present an approach to detect lateral spear phishing attacks in organisations in real-time. Their approach uses features derived from domain knowledge and analysis of characteristics pertaining to such attacks, combined with their scoring technique which works on non-labelled dataset. They evaluate the approach on several years' worth of real-world email dataset collected from volunteers in their institute. They were able to achieve false positive rate of below 1%, and also detected two instances of compromised accounts which were not known earlier. A comparison of their scoring technique with machine learning based anomaly detection techniques shows the proposed technique to be more suited for practical use. The proposed approach is primarily aimed at complementing existing detection techniques on email servers. However, they also developed a Chrome browser extension to demonstrate that such a system can also be used independently by organisations within their network.
机译:横向鱼叉式网络钓鱼攻击是一种强大的社会工程攻击,它是使用目标组织内的受感染电子邮件帐户进行的。由于这些攻击的性质,鱼叉式网络钓鱼攻击很难检测到。包含横向攻击向量使检测更具挑战性。作者提出了一种实时检测组织中横向鱼叉式网络钓鱼攻击的方法。他们的方法使用了从领域知识中衍生的特征以及与此类攻击有关的特征分析,并结合了适用于未标记数据集的评分技术。他们根据从其研究所的志愿者那里收集的几年来的真实电子邮件数据集来评估这种方法。他们能够实现低于1%的误报率,并且还发现了两个以前不为人知的受感染帐户实例。他们的计分技术与基于机器学习的异常检测技术的比较表明,所提出的技术更适合实际使用。提议的方法主要旨在补充电子邮件服务器上的现有检测技术。但是,他们还开发了Chrome浏览器扩展程序,以证明该系统也可以由其网络内的组织独立使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号