Tools and Techniques for Improving Cyber Situational Awareness of Targeted Phishing Attacks

被引:3
作者
Legg, Phil [1 ]
Blackman, Tim [2 ]
机构
[1] Univ West England, Dept Comp Sci & Creat Technol, Bristol, Avon, England
[2] Univ West England, Informat Technol Serv, Bristol, Avon, England
来源
2019 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA) | 2019年
关键词
Cyber situational awareness; phishing; visualisation; user experience;
D O I
10.1109/cybersa.2019.8899406
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing attacks continue to be one of the most common attack vectors used online today to deceive users, such that attackers can obtain unauthorised access or steal sensitive information. Phishing campaigns often vary in their level of sophistication, from mass distribution of generic content, such as delivery notifications, online purchase orders, and claims of winning the lottery, through to bespoke and highly-personalised messages that convincingly impersonate genuine communications (e.g., spearphishing attacks). There is a distinct trade-off here between the scale of an attack versus the effort required to curate content that is likely to convince an individual to carry out an action (typically, clicking a malicious hyperlink). In this short paper, we conduct a preliminary study on a recent realworld incident that strikes a balance between attacking at scale and personalised content. We adopt different visualisation tools and techniques for better assessing the scale and impact of the attack, that can be used both by security professionals to analyse the security incident, but could also be used to inform employees as a form of security awareness and training. We pitched the approach to IT professionals working in information security, who believe this may provide improved awareness of how targeted phishing campaigns can impact an organisation, and could contribute towards a pro-active step of how analysts will examine and mitigate the impact of future attacks across the organisation.
引用
收藏
页数:4
相关论文
共 50 条
  • [1] Cyber Attacks Analysis Using Decision Tree Technique for Improving Cyber Situational Awareness
    Pournouri, Sina
    Akhgar, Babak
    Bayerl, Petra Saskia
    GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: THE SECURITY CHALLENGES OF THE CONNECTED WORLD, ICGS3 2017, 2016, 630 : 155 - 172
  • [2] Improving Cyber Situational Awareness Through Data Mining and Predictive Analytic Techniques
    Pournouri, Sina
    Akhgar, Babak
    GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: TOMORROW'S CHALLENGES OF CYBER SECURITY, ICGS3 2015, 2015, 534 : 21 - 34
  • [3] A Cyber Security Situational Awareness Framework to Track and Project Multistage Cyber Attacks
    Bhatt, Parth
    Yano, Edgar Toshiro
    Amorim, Joni
    Gustavsson, Per
    PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS-2014), 2014, : 356 - 360
  • [4] NEWSROOM: Towards Automating Cyber Situational Awareness Processes and Tools for Cyber Defence
    Wurzenberger, Markus
    Krenn, Stephan
    Landauer, Max
    Skopik, Florian
    Perner, Cora
    Lotjonen, Jarno
    Paijanen, Jani
    Gardikis, Georgios
    Alabasis, Nikos
    Sakerman, Liisa
    Omri, Kristiina
    Lechner, Ulrike
    Schmitt, Corinna
    Roning, Juha
    Halunen, Kimmo
    Thouvenot, Vincent
    Weise, Martin
    Rauber, Andreas
    Gkioulos, Vasileios
    Katsikas, Sokratis
    Sabetta, Luigi
    Bonato, Jacopo
    Ortiz, Rocio
    Navarro, Daniel
    Stamatelatos, Nikolaos
    Avdoulas, Ioannis
    Mayer, Rudolf
    Ekelhart, Andreas
    Giannoulakis, Ioannis
    Kafetzakis, Emmanouil
    Corsi, Antonello
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [5] Cyber attacks real time detection: towards a Cyber Situational Awareness for naval systems
    Jacq, Olivier
    Brosset, David
    Kermarrec, Yvon
    Simonin, Jacques
    2019 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2019,
  • [6] Enhancing Cyber Situational Awareness: A New Perspective of Password Auditing Tools
    Stavrou, Eliana
    2018 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2018,
  • [7] Virtual reality for improving cyber situational awareness in security operations centers
    Munsinger, Brita
    Beebe, Nicole
    Richardson, Turquoise
    COMPUTERS & SECURITY, 2023, 132
  • [8] Tackling Verification and Validation Techniques to Evaluate Cyber Situational Awareness Capabilities
    Llopis Sanchez, Salvador
    Sandoval Rodriguez-Bermejo, David
    Daton Medenou, Roumen
    Pasqual de Riquelme, Ramis
    Torelli, Francesco
    Maestre Vidal, Jorge
    MATHEMATICS, 2022, 10 (15)
  • [9] Human-centered Assessment of Automated Tools for Improved Cyber Situational Awareness
    Strickson, Benjamin
    Worsley, Cameron
    Bertram, Stewart
    2023 15TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT, CYCON, 2023, : 273 - 286
  • [10] Analysis and Prevention of Phishing Attacks in Cyber Space
    Mishra, Alekh Kumar
    Tripathy, Asis Kumar
    Swain, Satyabrata
    2018 FIRST INTERNATIONAL CONFERENCE ON SECURE CYBER COMPUTING AND COMMUNICATIONS (ICSCCC 2018), 2018, : 430 - 434