SoK: A Comprehensive Reexamination of Phishing Research From the Security Perspective

SoK: A Comprehensive Reexamination of Phishing Research From the Security Perspective
复制标题

DOI:
10.1109/comst.2019.2957750
复制
发表时间:
2020-01-01
影响因子:
35.6
通讯作者:
Dunbar, Arthur
Dunbar, Arthur
中科院分区:
计算机科学1区
文献类型:
--
作者:
Das, Avisha;Baki, Shahryar;Dunbar, Arthur

文献摘要

被引文献

相似文献

网络钓鱼和鱼叉式网络钓鱼是伪装攻击的典型例子,因为信任是通过模仿来建立的,从而使攻击成功。鉴于这些攻击的普遍性,已经从多个维度对这些问题进行了大量研究。我们从安全领域的独特需求,即实时检测、主动攻击者、数据集质量和基础率谬论的角度,重新审视了网络钓鱼和鱼叉式网络钓鱼的现有研究。我们解释这些挑战,然后调查现有的网络钓鱼/鱼叉式网络钓鱼解决方案。这一观点巩固了文献,并阐明了改进现有解决方案的几个机会。我们根据不同攻击向量(例如,url,网站,电子邮件)的检测技术以及对用户意识的研究组织现有文献。对于检测技术,我们检查数据集的属性、特征提取、使用的检测算法和性能评估指标。这项工作可以帮助指导未来针对网络钓鱼、鱼叉式网络钓鱼和电子邮件伪装攻击的更有效防御的发展,并为彻底的评估和比较提供一个框架。
Phishing and spear phishing are typical examples of masquerade attacks since trust is built up through impersonation for the attack to succeed. Given the prevalence of these attacks, considerable research has been conducted on these problems along multiple dimensions. We reexamine the existing research on phishing and spear phishing from the perspective of the unique needs of the security domain, which we call security challenges: real-time detection, active attacker, dataset quality and base-rate fallacy. We explain these challenges and then survey the existing phishing/spear phishing solutions in their light. This viewpoint consolidates the literature and illuminates several opportunities for improving existing solutions. We organize the existing literature based on detection techniques for different attack vectors (e.g., URLs, websites, emails) along with studies on user awareness. For detection techniques we examine properties of the dataset, feature extraction, detection algorithms used, and performance evaluation metrics. This work can help guide the development of more effective defenses for phishing, spear phishing and email masquerade attacks of the future, as well as provide a framework for a thorough evaluation and comparison.