Skip to main content
QUICK REVIEW

[论文解读] Systematic Literature Review: Anti-Phishing Defences and Their Application to Before-the-click Phishing Email Detection

Trevor Wood, Vítor Basto-Fernandes|arXiv (Cornell University)|Apr 27, 2022
Spam and Phishing Detection被引用 4
一句话总结

本篇系统性文献回顾分析了21篇关于反钓鱼防御的原始研究,将技术分类为黑名单/白名单、启发式方法、内容分析、视觉识别、人工智能/机器学习以及主动防御方法。研究发现,尽管点击后检测技术已相当成熟,但点击前的钓鱼邮件检测——对于预防鱼叉式网络钓鱼等社会工程攻击至关重要——仍研究不足。其中,人工智能/机器学习与主动防御技术在用户交互前实现早期检测方面最具前景。

ABSTRACT

Most research into anti-phishing defence assumes that the mal-actor is attempting to harvest end-users' personally identifiable information or login credentials and, hence, focuses on detecting phishing websites. The defences for this type of attack are usually activated after the end-user clicks on a link, at which point the link is checked. This is known as after-the-click detection. However, more sophisticated phishing attacks (such as spear-phishing and whaling) are rarely designed to get the end-user to visit a website. Instead, they attempt to get the end-user to perform some other action, for example, transferring money from their bank account to the mal-actors account. These attacks are rarer, and before-the-click defence has been investigated less than after-the-click defence. To better integrate and contextualize these studies in the overall anti-phishing research, this paper presents a systematic literature review of proposed anti-phishing defences. From a total of 6330 papers, 21 primary studies and 335 secondary studies were identified and examined. The current research was grouped into six primary categories, blocklist/allowlist, heuristics, content, visual, artificial intelligence/machine learning and proactive, with an additional category of "other" for detection techniques that do not fit into any of the primary categories. It then discusses the performance and suitability of using these techniques for detecting phishing emails before the end-user even reads the email. Finally, it suggests some promising areas for further research.

研究动机与目标

  • 分析并分类学术研究中用于点击前钓鱼邮件检测的现有反钓鱼防御技术。
  • 识别出针对不依赖点击链接的复杂钓鱼攻击(如鱼叉式网络钓鱼和鲸钓攻击)的检测研究空白。
  • 评估不同检测技术在点击前邮件分析中的性能与适用性。
  • 通过突出尚未充分探索但前景广阔的防御方法,为未来研究提供指导。

提出的方法

  • 基于PRISMA指南对6,330篇文献进行系统性文献回顾,筛选出21篇原始研究和335篇二次研究。
  • 将检测技术划分为六大主要类别:黑名单/白名单、启发式方法、内容分析、视觉识别、人工智能/机器学习以及主动防御方法。
  • 评估每种技术在用户交互前检测钓鱼邮件的可行性与性能。
  • 基于报告的准确率、误报率及部署环境,评估各方法的成熟度与局限性。
  • 采用定性综合方法,比较各类别间检测机制的异同,识别研究重点与有效性的趋势。
  • 识别出有前景的研究方向,特别是人工智能/机器学习与主动防御机制在早期检测中的潜力。

实验结果

研究问题

  • RQ1在学术研究中,用于点击前钓鱼邮件检测的反钓鱼防御技术的主要类别有哪些?
  • RQ2现有检测技术在用户交互前识别钓鱼邮件方面的有效性如何,特别是在针对高级社会工程攻击时?
  • RQ3为何点击前检测的研究远少于点击后检测?其关键的技术与实际障碍是什么?
  • RQ4哪些检测技术(如人工智能/机器学习或主动防御方法)在早期识别钓鱼邮件方面最具潜力?
  • RQ5在提升点击前钓鱼邮件检测方面,存在哪些关键研究空白与未来发展方向?

主要发现

  • 绝大多数反钓鱼研究集中于点击后检测,仅识别出21篇原始研究专门针对点击前检测。
  • 人工智能/机器学习与主动检测技术在用户交互前识别钓鱼邮件方面展现出最高潜力,尤其在分析邮件内容与发件人行为方面。
  • 黑名单/白名单与基于启发式的方法对复杂攻击效果较差,因其依赖已知模式或签名。
  • 视觉识别方法在点击前分析中的应用有限,主要因邮件客户端中渲染与分析视觉钓鱼元素的复杂性。
  • ‘其他’类别(包括行为与上下文分析)揭示了新兴但尚未充分探索的方法,具有未来发展的高潜力。
  • 在真实世界条件下评估检测系统的研究所存在显著空白,大多数研究依赖合成或有限的数据集。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。