Spear Phishing Email Detection with Multiple Reputation Features and Sample Enhancement

被引:1
|
作者
Ling, Zhiting [1 ,2 ]
Feng, Huamin [3 ]
Ding, Xiong [4 ]
Wang, Xuren [5 ]
Gao, Chang [5 ]
Yang, Peian [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Beijing, Peoples R China
[3] Beijing Elect Sci & Technol Inst, Beijing, Peoples R China
[4] Hangzhou Dbappsecur Co Ltd, Beijing, Peoples R China
[5] Capital Normal Univ, Informat Engn Coll, Beijing, Peoples R China
来源
SCIENCE OF CYBER SECURITY, SCISEC 2022 | 2022年 / 13580卷
关键词
Spear phishing email; Threat intelligence; Reputation features; KM-SMOTE;
D O I
10.1007/978-3-031-17551-0_34
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Spear phishing is a complex targeted attack which has rapidly increased in recent years. The traditional email features based on the sender's behavior portrait cannot accurately characterize the spear phishing email, and the detection is often hampered when the data set is small. In order to tackle these problems, in this paper, we present a new approach for detecting spear phishing attacks in the full help of the local and external reputation features. Our method extracts 8 local and 6 external reputation features derived from an analysis of spear phishing emails, combined with 4 forwarding features and 20 general features for more accurate detection. Synthetic Minority Oversampling Technique (SMOTE) algorithm and an improved KM-SMOTE are applied on enhancing samples.We evaluate features on a multi-source data set of over 41 thousand emails and achieve the recall of 86.89%, the accuracy of 88.33% in identifying spear phishing emails. With SMOTE, we improve the recall and precision to 91.80% and 93.55%, and the false positive rate is reduced by at least 22%. With KM-SMOTE, we achieve better maximum recall of 95.08%, precision of 93.55% and F1-score of 94.31%.
引用
收藏
页码:522 / 538
页数:17
相关论文
共 50 条
  • [1] Phishing Susceptibility: An Investigation Into the Processing of a Targeted Spear Phishing Email
    Wang, Jingguo
    Herath, Tejaswini
    Chen, Rui
    Vishwanath, Arun
    Rao, H. Raghav
    IEEE TRANSACTIONS ON PROFESSIONAL COMMUNICATION, 2012, 55 (04) : 345 - 362
  • [2] Phishing Email Detection Based on Hybrid Features
    Yang, Zhuorao
    Qiao, Chen
    Kan, Wanling
    Qiu, Junji
    2018 4TH INTERNATIONAL CONFERENCE ON ENVIRONMENTAL SCIENCE AND MATERIAL APPLICATION, 2019, 252
  • [3] Phishing Email Detection Technique by using Hybrid Features
    Form, Lew May
    Chiew, Kang Leng
    Sze, San Nah
    Tiong, Wei King
    2015 9TH INTERNATIONAL CONFERENCE ON IT IN ASIA (CITA), 2015,
  • [4] A Study of Preventing Email (Spear) Phishing by Enabling Human Intelligence
    Stembert, Nathalie
    Padmos, Arne
    Bargh, Mortaza S.
    Choenni, Sunil
    Jansen, Frans
    2015 EUROPEAN INTELLIGENCE AND SECURITY INFORMATICS CONFERENCE (EISIC), 2015, : 113 - 120
  • [5] Enhancing phishing email detection with stylometric features and classifier stacking
    Chanis, Ilias
    Arampatzis, Avi
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2025, 24 (01)
  • [6] Overconfidence in Phishing Email Detection
    Wang, Jingguo
    Li, Yuan
    Rao, H. Raghav
    JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2016, 17 (11): : 759 - 783
  • [7] Email Embeddings for Phishing Detection
    Gutierrez, Luis Felipe
    Abri, Faranak
    Armstrong, Miriam
    Namin, Akbar Siami
    Jones, Keith S.
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 2087 - 2092
  • [8] A Game Theoretical Model for Anticipating Email Spear-Phishing Strategies
    Tchakounte, Franklin
    Nyassi, Virgile Sime
    Danga, Duplex Elvis Houpa
    Udagepola, Kalum Priyanath
    Atemkeng, Marcellin
    EAI ENDORSED TRANSACTIONS ON SCALABLE INFORMATION SYSTEMS, 2021, 8 (30) : 1 - 24
  • [9] Cue Utilization, Phishing Feature and Phishing Email Detection
    Bayl-Smith, Piers
    Sturman, Daniel
    Wiggins, Mark
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2020, 2020, 12063 : 56 - 70
  • [10] Optimizing Personalized Email Filtering Thresholds to Mitigate Sequential Spear Phishing Attacks
    Zhao, Mengchen
    An, Bo
    Kiekintveld, Christopher
    THIRTIETH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2016, : 658 - 664