首页> 外文OA文献 >Taking the bait: A systems analysis of phishing attacks
【2h】

Taking the bait: A systems analysis of phishing attacks

机译:诱饵:网络钓鱼攻击的系统分析

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Phishing attacks are a common feature of online communications. Phishing attacks impact many actors, from individual victims to the corporate and government agencies whose brands are deceptively used. Responding to phishing is big business, driving software security markets, influencing eCommerce uptake and participation, and protecting corporate brand and image. Yet despite its insidious nature and the penetration of phishing throughout online communications, little is known regarding phishing attacks and their responses. This paper is a response to this key knowledge gap, analyzing the tasks and mapping the social interactions of a phishing attack and the associated response. To achieve this, the research team adopted a multi-method approach in examining the underlying functions and interactions involved in a phishing attack and its response by deliberately ‘taking the phishing bait’, interviewing a sample of individuals that had unwittingly responded to phishing attacks, and engaging with organisations that took response measures to such events. This multi-actor engagement provided critical observations and content about the victim experience and interactions with those responsible for the attacks. The research is highly novel in its application of Work Domain Analysis (WDA) to gain an understanding of the functional structure of phishing attacks and the online transactional environment they target as a sociotechnical system. By examining the functional properties of interactions within the research context, the paper provides a unique perspective of phishing and the inter-linkages and dependencies across multiple levels of abstraction from the initial ‘baiting’ to the achievement of overall system objectives by cybercriminals. The findings provide opportunities to enhance phishing prevention and detection methodologies, improve individual resilience to such attacks, and pave the way for future efforts in applying sociotechnical systems methods to the cybercrime environment.
机译:网络钓鱼攻击是在线通信的常见功能。网络钓鱼攻击影响到许多行为者,从个人受害者到欺骗性使用品牌的公司和政府机构。对网络钓鱼的响应是大企业,它推动了软件安全市场,影响了电子商务的采用和参与,并保护了企业品牌和形象。然而,尽管其具有阴险的性质以及网络钓鱼在整个在线通信中的渗透,但对于网络钓鱼攻击及其响应知之甚少。本文是对这一关键知识差距的一种回应,它分析了网络钓鱼攻击的任务并绘制了社交互动以及相关回应的地图。为了实现这一目标,研究小组采用了一种多方法方法,通过有意地“诱骗网络钓鱼诱饵”,并访问了对网络钓鱼攻击无意中做出响应的个人样本,来检查网络钓鱼攻击所涉及的潜在功能和交互及其响应。并与对此类事件采取了应对措施的组织合作。这种多参与者参与提供了有关受害者经历以及与攻击负责人的互动的重要观察和内容。该研究在工作域分析(WDA)的应用中是非常新颖的,以了解网络钓鱼攻击的功能结构以及它们作为一种社会技术系统所针对的在线交易环境。通过研究研究环境中交互的功能特性,本文提供了网络钓鱼的独特视角以及从最初的“诱饵”到网络犯罪分子实现总体系统目标的跨多个抽象级别的相互联系和依赖性。这些发现为增强网络钓鱼预防和检测方法,增强个人对此类攻击的抵御能力以及为将来将社会技术系统方法应用于网络犯罪环境的努力铺平道路提供了机会。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号