vix.ing · top · new · best · stats · spec

SOK: A Comprehensive Reexamination of Phishing Research from the\n Security Perspective

2019/11/03 by Avisha Das, Das, Avisha, Shahryar Baki +7 · 3 citations
Computer Science · #Advanced Malware Detection Techniques #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Spam and Phishing Detection #User Authentication and Security Systems

paper · pdf · doi:10.48550/arxiv.1911.00953

openalex publication_date 2019/11/03 · openalex created_date 2022/07/26 · openalex updated_date 2026/07/28

Abstract

Phishing and spear-phishing are typical examples of masquerade attacks since\ntrust is built up through impersonation for the attack to succeed. Given the\nprevalence of these attacks, considerable research has been conducted on these\nproblems along multiple dimensions. We reexamine the existing research on\nphishing and spear-phishing from the perspective of the unique needs of the\nsecurity domain, which we call security challenges: real-time detection, active\nattacker, dataset quality and base-rate fallacy. We explain these challenges\nand then survey the existing phishing/spear phishing solutions in their light.\nThis viewpoint consolidates the literature and illuminates several\nopportunities for improving existing solutions. We organize the existing\nliterature based on detection techniques for different attack vectors (e.g.,\nURLs, websites, emails) along with studies on user awareness. For detection\ntechniques, we examine properties of the dataset, feature extraction, detection\nalgorithms used, and performance evaluation metrics. This work can help guide\nthe development of more effective defenses for phishing, spear-phishing, and\nemail masquerade attacks of the future, as well as provide a framework for a\nthorough evaluation and comparison.\n

Cited by

Related