Reading Between the Lines: Content-Agnostic Detection of Spear-Phishing Emails

被引:15
|
作者
Gascon, Hugo [1 ]
Ullrich, Steffen [2 ]
Stritter, Benjamin [3 ]
Rieck, Konrad [1 ]
机构
[1] TU Braunschweig, Braunschweig, Germany
[2] Genua GmbH, Kirchheim, Germany
[3] Friedrich Alexander Univ Erlangen Nurnberg, Erlangen, Germany
关键词
Spear-phishing; Email spoofing; Targeted attack detection;
D O I
10.1007/978-3-030-00470-5_4
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Spear-phishing is an effective attack vector for infiltrating companies and organisations. Based on the multitude of personal information available online, an attacker can craft seemingly legit emails and trick his victims into opening malicious attachments and links. Although anti-spoofing techniques exist, their adoption is still limited and alternative protection approaches are needed. In this paper, we show that a sender leaves content-agnostic traits in the structure of an email. Based on these traits, we develop a method capable of learning profiles for a large set of senders and identifying spoofed emails as deviations thereof. We evaluate our approach on over 700,000 emails from 16,000 senders and demonstrate that it can discriminate thousands of senders, identifying spoofed emails with 90% detection rate and less than 1 false positive in 10,000 emails. Moreover, we show that individual traits are hard to guess and spoofing only succeeds if entire emails of the sender are available to the attacker.
引用
收藏
页码:69 / 91
页数:23
相关论文
共 19 条
  • [11] CJ-Sniffer: Measurement and Content-Agnostic Detection of Cryptojacking Traffic
    Feng, Yebo
    Li, Jun
    Sisodia, Devkishen
    PROCEEDINGS OF 25TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2022, 2022, : 482 - 494
  • [12] Towards reliable online clickbait video detection: A content-agnostic approach
    Shang, Lanyu
    Zhang, Daniel
    Wang, Michael
    Lai, Shuyue
    Wang, Dong
    KNOWLEDGE-BASED SYSTEMS, 2019, 182
  • [13] Towards Learning-Based, Content-Agnostic Detection of Social Bot Traffic
    Feng, Yebo
    Li, Jun
    Jiao, Lei
    Wu, Xintao
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (05) : 2149 - 2163
  • [14] READING BETWEEN THE LINES IN CONTENT AREAS USING CLASSIFYING REASONING
    PAUL, RH
    JOURNAL OF READING, 1990, 34 (02): : 92 - 97
  • [15] Reading Between the Lines: A Prototype Model for Detecting Twitter Sockpuppet Accounts Using Language-Agnostic Processes
    Crabb, Erin Smith
    Mishler, Alan
    Paletz, Susannah
    Hefright, Brook
    Golonka, Ewa
    HCI INTERNATIONAL 2015 - POSTERS' EXTENDED ABSTRACTS, PT I, 2015, 528 : 656 - 661
  • [16] LISTENING BETWEEN THE LINES: SYNTHETIC SPEECH DETECTION DISREGARDING VERBAL CONTENT
    Salvi, Davide
    Balcha, Temesgen Semu
    Bestagini, Paolo
    Tubaro, Stefano
    2024 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING WORKSHOPS, ICASSPW 2024, 2024, : 883 - 887
  • [17] Reading between the lines: untwining online user-generated content using sentiment analysis
    Rasool, Gowhar
    Pathania, Anjali
    JOURNAL OF RESEARCH IN INTERACTIVE MARKETING, 2021, 15 (03) : 401 - 418
  • [18] Reading between the Lines: Image-Based Order Detection in OCR for Chinese Historical Documents
    Ma, Hsing-Yuan
    Huang, Hen-Hsen
    Liu, Chao-Lin
    THIRTY-EIGTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 21, 2024, : 23808 - 23810
  • [19] Reading Between the Lines: Machine Learning Ensemble and Deep Learning for Implied Threat Detection in Textual Data
    Raza, Muhammad Owais
    Meghji, Areej Fatemah
    Mahoto, Naeem Ahmed
    Al Reshan, Mana Saleh
    Abosaq, Hamad Ali
    Sulaiman, Adel
    Shaikh, Asadullah
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2024, 17 (01)