Skip to main content
QUICK REVIEW

[Paper Review] Why Johnny can't rely on anti-phishing educational interventions to protect himself against contemporary phishing attacks?

Matheesha Fernando, Nalin Asanka Gamagedara Arachchilage|arXiv (Cornell University)|Apr 28, 2020
Spam and Phishing Detection18 references4 citations
TL;DR

This paper investigates the effectiveness of current anti-phishing educational interventions against modern phishing techniques, revealing that outdated teaching content—particularly focusing on IP-based URL obfuscation—fails to address emerging attack methods. The study finds two novel obfuscation techniques (punycode and homoglyphs) used in contemporary phishing attacks are absent from existing educational materials, undermining user protection despite educational efforts.

ABSTRACT

Phishing is a way of stealing people's sensitive information such as username, password and banking details by disguising as a legitimate entity (i.e. email, website). Anti-phishing education considered to be vital in strengthening "human", the weakest link in information security. Previous research in anti-phishing education focuses on improving educational interventions to better interact the end user. However, one can argue that existing anti-phishing educational interventions are limited in success due to their outdated teaching content incorporated. Furthermore, teaching outdated anti-phishing techniques might not help combat contemporary phishing attacks. Therefore, this research focuses on investigating the obfuscation techniques of phishing URLs used in anti-phishing education against the contemporary phishing attacks reported in PhishTank.com. Our results showed that URL obfuscation with IP address has become insignificant and it revealed two emerging URL obfuscation techniques, that attackers use lately, haven't been incorporated into existing anti-phishing educational interventions.

Motivation & Objective

  • To evaluate the relevance of existing anti-phishing educational interventions against current phishing attack techniques.
  • To identify emerging URL obfuscation techniques used in contemporary phishing attacks.
  • To assess whether current educational content addresses these new obfuscation methods.
  • To highlight the gap between modern phishing tactics and traditional anti-phishing training.
  • To advocate for updating educational curricula to include emerging phishing techniques.

Proposed method

  • Analyzed a dataset of contemporary phishing URLs reported in the specified URL source.
  • Identified and categorized URL obfuscation techniques used in modern phishing attacks.
  • Compared these obfuscation techniques against the content of existing anti-phishing educational interventions.
  • Evaluated the alignment between current educational materials and real-world phishing tactics.
  • Focused on identifying missing or outdated teaching points in educational content, particularly regarding URL structure and obfuscation.
  • Used qualitative and comparative analysis to assess the relevance of educational content to current threats.

Experimental results

Research questions

  • RQ1Are current anti-phishing educational interventions effective against modern phishing attacks?
  • RQ2What are the dominant URL obfuscation techniques used in contemporary phishing attacks?
  • RQ3To what extent do existing anti-phishing educational materials cover these emerging obfuscation techniques?
  • RQ4Why do traditional anti-phishing education programs fail to protect users from modern phishing threats?
  • RQ5What specific obfuscation techniques are missing from current educational content?

Key findings

  • The use of IP addresses in obfuscated URLs has become largely insignificant in modern phishing attacks.
  • Two emerging obfuscation techniques—punycode and homoglyphs—have not been incorporated into existing anti-phishing educational interventions.
  • Phishing attacks increasingly use visual and technical obfuscation that bypasses traditional user awareness training.
  • Existing educational content remains focused on outdated techniques, such as recognizing IP-based URLs, which are no longer prevalent.
  • The gap between current educational content and real-world phishing tactics undermines the effectiveness of anti-phishing training.
  • There is a critical need to update anti-phishing education to include modern obfuscation methods like homoglyphs and punycode to improve user resilience.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.