EmailProfiler: Spearphishing Filtering with Header and Stylometric Features of Emails

被引:40
|
作者
Duman, Sevtap [1 ]
Cakmakci, Kubra Kalkan [2 ]
Egele, Manuel [3 ]
Robertson, William [1 ]
Kirda, Engin [1 ]
机构
[1] Northeastern Univ, Coll Comp & Informat Sci, Boston, MA 02115 USA
[2] Bogazici Univ, Dept Engn, Istanbul, Turkey
[3] Boston Univ, Elect & Comp Engn, Boston, MA 02215 USA
关键词
EMOTION-RECOGNITION; COMPLEX EMOTIONS; CHILDREN; AUTISM; MIND;
D O I
10.1109/COMPSAC.2016.105
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Spearphishing is a prominent targeted attack vector in today's Internet. By impersonating trusted email senders through carefully crafted messages and spoofed metadata, adversaries can trick victims into launching attachments containing malicious code or into clicking on malicious links that grant attackers a foothold into otherwise well-protected networks. Spearphishing is effective because it is fundamentally difficult for users to distinguish legitimate emails from spearphishing emails without additional defensive mechanisms. However, such mechanisms, such as cryptographic signatures, have found limited use in practice due to their perceived difficulty of use for normal users. In this paper, we present a novel automated approach to defending users against spearphishing attacks. The approach first builds probabilistic models of both email metadata and stylometric features of email content. Then, subsequent emails are compared to these models to detect characteristic indicators of spearphishing attacks. Several instantiations of this approach are possible, including performing model learning and evaluation solely on the receiving side, or senders publishing models that can be checked remotely by the receiver. Our evaluation of a real data set drawn from 20 email users demonstrates that the approach effectively discriminates spearphishing attacks from legitimate email while providing significant ease-of-use benefits over traditional defenses.
引用
收藏
页码:408 / 416
页数:9
相关论文
共 50 条
  • [1] Analyzing Social and Stylometric Features to Identify Spear phishing Emails
    Dewan, Prateek
    Kashyap, Anand
    Kumaraguru, Ponnurangam
    PROCEEDINGS OF THE 2014 APWG SYMPOSIUM ON ELECTRONIC CRIME RESEARCH (ECRIME), 2014,
  • [2] Combining visual and textual features for filtering spam emails
    Gargiulo, Francesco
    Sansone, Carlo
    19TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION, VOLS 1-6, 2008, : 2702 - 2705
  • [3] A Survey on Stylometric Text Features
    Lagutina, Ksenia
    Lagutina, Nadezhda
    Boychuk, Elena
    Vorontsova, Inna
    Shliakhtina, Elena
    Belyaeva, Olga
    Paramonov, Ilya
    PROCEEDINGS OF THE 2019 25TH CONFERENCE OF OPEN INNOVATIONS ASSOCIATION (FRUCT), 2019, : 184 - 195
  • [4] Evaluating spam filters and Stylometric Detection of AI-generated phishing emails
    Opara, Chidimma
    Modesti, Paolo
    Golightly, Lewis
    EXPERT SYSTEMS WITH APPLICATIONS, 2025, 276
  • [5] Filtering a Reference Corpus to Generalize Stylometric Representations
    Hay, Julien
    Doan, Bich-Lien
    Popineau, Fabrice
    Elhara, Ouassim Ait
    PROCEEDINGS OF THE 12TH INTERNATIONAL JOINT CONFERENCE ON KNOWLEDGE DISCOVERY, KNOWLEDGE ENGINEERING AND KNOWLEDGE MANAGEMENT (KDIR), VOL 1, 2020, : 259 - 268
  • [6] Using Stylometric Features for Sentiment Classification
    Anchieta, Rafael T.
    Ricarte Neto, Francisco Assis
    de Sousa, Rogerio Figueiredo
    Moura, Raimundo Santos
    COMPUTATIONAL LINGUISTICS AND INTELLIGENT TEXT PROCESSING (CICLING 2015), PT II, 2015, 9042 : 189 - 200
  • [7] Finding Characteristic Features in Stylometric Analysis
    Klaussner, Carmen
    Nerbonne, John
    Coltekin, Cagri
    DIGITAL SCHOLARSHIP IN THE HUMANITIES, 2015, 30 : 114 - 129
  • [8] Optical header recognition by spectroholographic filtering
    Shen, XA
    Kachru, R
    OPTICS LETTERS, 1995, 20 (24) : 2508 - 2510
  • [9] Efficient spam filtering based on informative features extracted from the header fields and the urls in the message
    Qaroush, Aziz
    Washaha, Mahdi
    Khater, Ismail
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2014, 29 (01): : 19 - 31
  • [10] Stylometric Features for Authorship Attribution of Polish Texts
    Szwed, Piotr
    ARTIFICIAL INTELLIGENCE AND SOFT COMPUTING, ICAISC 2017, PT II, 2017, 10246 : 171 - 182