Chrome Extension
WeChat Mini Program
Use on ChatGLM

Analysis of publicly available anti-phishing webpages: contradicting information, lack of concrete advice and very narrow attack vector

2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)(2020)

Cited 4|Views12
No score
Abstract
Phishing is currently one of the biggest threats in cybersecurity for both the business and the private contexts. A large percentage of phishing attacks are blocked by automated technical solutions, but unfortunately there is often a delay between when phishing emails enter inboxes and when the technical solutions are able to detect and filter them out. To close this gap, it is common practice for companies to implement mandatory phishing awareness measures for their employees. But what about the private context? We aimed at answering that question by analysing 94 anti-phishing webpages from eight different countries and four organisation types. Our analysis revealed not only contradicting recommendations, but also that most of them are rather abstract (e.g. check the URL before clicking on the link without telling what to look for) and lack guidance on advanced phishing techniques (e.g. clone phishing). We discuss the problems faced by readers of these webpages and outline both immediate recommendations to the web designer and ways forward to improve the current situation as future work.
More
Translated text
Key words
phishing,user awareness,anti-phishing recommendations,anti-phishing material
AI Read Science
Must-Reading Tree
Example
Generate MRT to find the research sequence of this paper
Chat Paper
Summary is being generated by the instructions you defined