An Anti-phishing Training System for Security Awareness and Education Considering Prevention of Information Leakage

被引:0
|
作者
Higashino, Masayuki [1 ]
Kawato, Toshiya [2 ]
Ohmori, Motoyuki [1 ]
Kawamura, Takao [1 ]
机构
[1] Tottori Univ, Tottori, Japan
[2] Natl Inst Technol, Yonago Coll, Yonago, Tottori, Japan
来源
5TH INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT (ICIM 2019) | 2019年
关键词
anti-phishing training system; anti-phishing awareness training; phishing e-mails; phishing sites; phishing;
D O I
10.1109/infoman.2019.8714691
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Phishing is one of the dangerous threats to organisations. A sender of a phishing e-mail pretends to be a trusted person or a system in order to steal valuable information including personal identity data and credentials. In order to deal with this problem, many organisations have implemented an anti-phishing training. However, the outsourcing of an anti-phishing training requires a high cost. Additionally, many anti-phishing training systems provided by vendors save sensitive data such as e-mail addresses and names of trainees to public servers for an anti-phishing training. This architecture has a problem that attacking these public servers increases for the risk of information leakage about trainees. Therefore, this paper proposes an anti-phishing training system which does not save sensitive data such as an e-mail address and a name of trainees to public servers, and it is implementable at a low cost. This proposed system saves sensitive data to a trainer's local computer instead of public servers. A sensitive data saved on a trainer's local computer and trainees' access log data on public servers are associated with a pseudonym generated via pseudonymisation technique. Thus, if attackers try to steal trainees' sensitive data via the Internet, it becomes difficult for attackers by deleting sensitive data on a trainer's local computer.
引用
收藏
页码:82 / 86
页数:5
相关论文
共 50 条
  • [1] An Anti-Phishing System Employing Diffused Information
    Chen, Teh-Chung
    Stepan, Torin
    Dick, Scott
    Miller, James
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2014, 16 (04)
  • [2] Anti-Phishing Awareness Delivery Methods
    Darem, Abdulbasit
    ENGINEERING TECHNOLOGY & APPLIED SCIENCE RESEARCH, 2021, 11 (06) : 7944 - 7949
  • [3] An information-sharing based anti-phishing system
    Cheng, Yueqing
    Yuan, Zhen
    Ma, Lei
    Deng, Robert H.
    PROCEEDINGS OF THE FIRST INTERNATIONAL SYMPOSIUM ON DATA, PRIVACY, AND E-COMMERCE, 2007, : 265 - +
  • [4] Visual security is feeble for Anti-Phishing
    Leung, Chun-Ming
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON ANTI-COUNTERFEITING, SECURITY, AND IDENTIFICATION IN COMMUNICATION, 2009, : 118 - 123
  • [5] NoPhish: An anti-phishing education app
    Canova, Gamze
    Volkamer, Melanie
    Bergmann, Clemens
    Borza, Roland
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2014, 8743 : 88 - 192
  • [6] NoPhish: An Anti-Phishing Education App
    Canova, Gamze
    Volkamer, Melanie
    Bergmann, Clemens
    Borza, Roland
    SECURITY AND TRUST MANAGEMENT (STM 2014), 2014, 8743 : 188 - 192
  • [7] Evaluation of the Effective Anti-Phishing Awareness and Training in Governmental and Private Organizations in Riyadh
    Innab, Nisreen
    Al-Rashoud, Haifa
    Al-Mahawes, Riham
    Al-Shehri, Wauood
    2018 21ST SAUDI COMPUTER SOCIETY NATIONAL COMPUTER CONFERENCE (NCC), 2018,
  • [8] NoPhish: An anti-phishing education app
    Technische Universität Darmstadt, Germany
    Lect. Notes Comput. Sci., (188-192):
  • [9] A Design of an Anti-Phishing Training System Collaborated with Multiple Organizations
    Higashino, Masayuki
    IIWAS2019: THE 21ST INTERNATIONAL CONFERENCE ON INFORMATION INTEGRATION AND WEB-BASED APPLICATIONS & SERVICES, 2019, : 589 - 592
  • [10] Development of an E-Learning Content-Making System for Information Security (ELSEC) and Its Application to Anti-Phishing Education
    Kawakami, Masatoshi
    Yasuda, Hiroshi
    Sasaki, Ryoichi
    2010 INTERNATIONAL CONFERENCE ON E-EDUCATION, E-BUSINESS, E-MANAGEMENT AND E-LEARNING: IC4E 2010, PROCEEDINGS, 2010, : 7 - 11