论文标题

约翰尼为什么不能依靠反捕捞教育干预措施来保护自己免受当代的网络钓鱼攻击?

Why Johnny can't rely on anti-phishing educational interventions to protect himself against contemporary phishing attacks?

论文作者

Fernando, Matheesha, Arachchilage, Nalin Asanka Gamagedara

论文摘要

网络钓鱼是一种通过合法实体(即电子邮件,网站)掩饰来窃取人们的敏感信息,例如用户名,密码和银行详细信息。反向钓鱼教育被认为对加强“人类”是至关重要的,这是信息安全中最薄弱的联系。先前在反钓鱼教育方面的研究重点是改善教育干预措施,以更好地与最终用户相互作用。但是,人们可以说,由于其过时的教学内容纳入了现有的反向钓鱼教育干预措施,因此成功的限制是有限的。此外,教过过时的反钓鱼技术可能无助于对抗当代的网络钓鱼攻击。因此,这项研究重点是调查反钓鱼教育中用于针对Phishtank.com报道的当代网络钓鱼攻击的网络钓鱼URL的混淆技术。我们的结果表明,与IP地址的URL混淆已经变得微不足道,它揭示了两种新兴的URL混淆技术,最近攻击者使用的是攻击者,但尚未纳入现有的反钓鱼教育干预措施中。

Phishing is a way of stealing people's sensitive information such as username, password and banking details by disguising as a legitimate entity (i.e. email, website). Anti-phishing education considered to be vital in strengthening "human", the weakest link in information security. Previous research in anti-phishing education focuses on improving educational interventions to better interact the end user. However, one can argue that existing anti-phishing educational interventions are limited in success due to their outdated teaching content incorporated. Furthermore, teaching outdated anti-phishing techniques might not help combat contemporary phishing attacks. Therefore, this research focuses on investigating the obfuscation techniques of phishing URLs used in anti-phishing education against the contemporary phishing attacks reported in PhishTank.com. Our results showed that URL obfuscation with IP address has become insignificant and it revealed two emerging URL obfuscation techniques, that attackers use lately, haven't been incorporated into existing anti-phishing educational interventions.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源