Detecting and Characterizing Lateral Phishing at Scale

Detecting and Characterizing Lateral Phishing at Scale
复制标题

DOI:
--
复制
发表时间:
2019-10
期刊:
--
影响因子:
--
通讯作者:
Grant Ho;Asaf Cidon;Lior Gavish;M. Schweighauser;V. Paxson;S. Savage;G. Voelker;D. Wagner
Grant Ho;Asaf Cidon;Lior Gavish;M. Schweighauser;V. Paxson;S. Savage;G. Voelker;D. Wagner
中科院分区:
其他
文献类型:
--
作者:
Grant Ho;Asaf Cidon;Lior Gavish;M. Schweighauser;V. Paxson;S. Savage;G. Voelker;D. Wagner

文献摘要

被引文献

相似文献

作者:Ho, G;西东,A;加维什,L;施魏格豪瑟,M;帕克森,V;萨维奇,S;沃尔克,总经理;瓦格纳,D |摘要:© 2019 USENIX 协会。版权所有。我们基于来自 92 个企业组织的 1.13 亿封员工发送的电子邮件的数据集,首次大规模描述了横向网络钓鱼攻击。在横向网络钓鱼攻击中,攻击者利用受损的企业帐户向其他用户发送网络钓鱼电子邮件,从隐式信任和被劫持用户帐户中的信息中获益。我们开发了一个分类器,可以发现数百封真实世界的横向网络钓鱼电子邮件,同时每百万员工发送的电子邮件产生不到四个误报。根据我们检测到的攻击以及用户报告事件的语料库,我们量化了横向网络钓鱼的规模,识别了攻击者遵循的几种主题内容和收件人目标策略,阐明了攻击者表现出的两种复杂行为,并估计了这些攻击的成功率。总的来说,这些结果扩展了我们对“企业攻击者”的心理模型,并揭示了企业网络钓鱼攻击的现状。
Author(s): Ho, G; Cidon, A; Gavish, L; Schweighauser, M; Paxson, V; Savage, S; Voelker, GM; Wagner, D | Abstract: © 2019 by The USENIX Association. All rights reserved. We present the first large-scale characterization of lateral phishing attacks, based on a dataset of 113 million employee-sent emails from 92 enterprise organizations. In a lateral phishing attack, adversaries leverage a compromised enterprise account to send phishing emails to other users, benefit-ting from both the implicit trust and the information in the hijacked user's account. We develop a classifier that finds hundreds of real-world lateral phishing emails, while generating under four false positives per every one-million employee-sent emails. Drawing on the attacks we detect, as well as a corpus of user-reported incidents, we quantify the scale of lateral phishing, identify several thematic content and recipient targeting strategies that attackers follow, illuminate two types of sophisticated behaviors that attackers exhibit, and estimate the success rate of these attacks. Collectively, these results expand our mental models of the 'enterprise attacker' and shed light on the current state of enterprise phishing attacks.