Anti-phishing: A comprehensive perspective

被引:2
|
作者
Varshney, Gaurav [1 ]
Kumawat, Rahul [2 ]
Varadharajan, Vijay [3 ]
Tupakula, Uday [3 ]
Gupta, Chandranshu [1 ]
机构
[1] Indian Inst Technol Jammu, Jammu, India
[2] Amazon Dev Ctr, Chennai, India
[3] Univ Newcastle, Callaghan, Australia
关键词
Anti-phishing; Phishing; Deception; Cyber laws; Social and cognitive factors; WEBSITES; AUTHENTICATION; BEHAVIOR; SCHEME; SOK;
D O I
10.1016/j.eswa.2023.122199
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Phishing is a form of deception technique that attackers often use to acquire sensitive information related to individuals and organizations fraudulently. Although Phishing attacks have been known for more than two decades, and there is ongoing research for developing effective techniques against these attacks, the increasing trend of attacks confirms the lack of robust solutions and techniques against these attacks. According to Trend Micro, over 90 percent of all Cybersecurity attacks begin with spear Phishing emails and hence there is a need for comprehensive research in the area of anti-Phishing to improve the overall Cybersecurity landscape. This paper, therefore, performs a comprehensive study and analysis of past research work in anti-Phishing. The survey also tries to study various relationships such as those between the Phishers and the motives behind Phishing and explores/assesses various tactics that are employed for launching Phishing attacks. Highlighting the role of social and cognitive factors in the success of a Phishing attack which was not focused on in earlier reviews, is one of the major contributions of this work. The paper also provides a detailed understanding of the types of Phishers and the type of Phishing performed by them with a comprehensive classification of antiPhishing detection/prevention/awareness solutions through a systematic literature review. The contributions of leading organizations and their active role through various anti-Phishing products are also discussed in this paper to bring light to the research and development happening in the industry with respect to anti-Phishing. Finally, the cyber laws to handle Phishing attacks in various countries have been presented for readers' interest. We believe this survey brings new knowledge and a comprehensive perspective to its readers from academia and industry to explore new horizons for research activities in anti-Phishing.
引用
收藏
页数:34
相关论文
共 50 条
  • [41] 2 Years in the anti-phishing group of a large company
    Gallo, Luigi
    Maiello, Alessandro
    Botta, Alessio
    Ventre, Giorgio
    [J]. COMPUTERS & SECURITY, 2021, 105
  • [42] Survey paper: Taxonomy of website anti-phishing solutions
    Zaimi, Rania
    Hafidi, Mohamed
    Lamia, Mahnane
    [J]. 2020 SEVENTH INTERNATIONAL CONFERENCE ON SOCIAL NETWORK ANALYSIS, MANAGEMENT AND SECURITY (SNAMS), 2020, : 101 - 108
  • [43] Efficacy of Anti-phishing Measures and Strategies - A research Analysis
    Bindra, Gundeep Singh
    [J]. World Academy of Science, Engineering and Technology, 2010, 69 : 366 - 372
  • [44] A Survey on Anti-phishing techniques in Mobile Phones.
    Chorghe, Sharvari Prakash
    Shekokar, Narendra
    [J]. 2016 INTERNATIONAL CONFERENCE ON INVENTIVE COMPUTATION TECHNOLOGIES (ICICT), VOL 2, 2016, : 556 - 560
  • [45] An information-sharing based anti-phishing system
    Cheng, Yueqing
    Yuan, Zhen
    Ma, Lei
    Deng, Robert H.
    [J]. PROCEEDINGS OF THE FIRST INTERNATIONAL SYMPOSIUM ON DATA, PRIVACY, AND E-COMMERCE, 2007, : 265 - +
  • [46] iTrustPage: A User-Assisted Anti-Phishing Tool
    Ronda, Troy
    Saroiu, Stefan
    Wolman, Alec
    [J]. EUROSYS'08: PROCEEDINGS OF THE EUROSYS 2008 CONFERENCE, 2008, : 261 - 272
  • [47] B-APT: Bayesian Anti-Phishing Toolbar
    Likarish, Peter
    Jung, Eunjin
    Dunbar, Don
    Hansen, Thomas E.
    Hourcade, Juan Pablo
    [J]. 2008 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, PROCEEDINGS, VOLS 1-13, 2008, : 1745 - +
  • [48] AN ANTI-PHISHING MODEL FOR ECOMMERCE UNDER A NETWORK ENVIRONMENT
    Cheng, Yifei
    Li, Gen
    [J]. ICEIS 2011: PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL 1, 2011, : 400 - 404
  • [49] An Anti-Phishing Kit Scheme for Secure Web Transactions
    Orunsolu, A. A.
    Sodiya, A. S.
    [J]. ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 15 - 24
  • [50] FINANCIAL WEBSITES ORIENTED HEURISTIC ANTI-PHISHING RESEARCH
    Liu, Yang
    Zhang, Miao
    [J]. 2012 IEEE 2ND INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND INTELLIGENT SYSTEMS (CCIS) VOLS 1-3, 2012, : 614 - 618