Tools and Techniques for Improving Cyber Situational Awareness of Targeted Phishing Attacks

被引:3
作者
Legg, Phil [1 ]
Blackman, Tim [2 ]
机构
[1] Univ West England, Dept Comp Sci & Creat Technol, Bristol, Avon, England
[2] Univ West England, Informat Technol Serv, Bristol, Avon, England
来源
2019 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA) | 2019年
关键词
Cyber situational awareness; phishing; visualisation; user experience;
D O I
10.1109/cybersa.2019.8899406
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing attacks continue to be one of the most common attack vectors used online today to deceive users, such that attackers can obtain unauthorised access or steal sensitive information. Phishing campaigns often vary in their level of sophistication, from mass distribution of generic content, such as delivery notifications, online purchase orders, and claims of winning the lottery, through to bespoke and highly-personalised messages that convincingly impersonate genuine communications (e.g., spearphishing attacks). There is a distinct trade-off here between the scale of an attack versus the effort required to curate content that is likely to convince an individual to carry out an action (typically, clicking a malicious hyperlink). In this short paper, we conduct a preliminary study on a recent realworld incident that strikes a balance between attacking at scale and personalised content. We adopt different visualisation tools and techniques for better assessing the scale and impact of the attack, that can be used both by security professionals to analyse the security incident, but could also be used to inform employees as a form of security awareness and training. We pitched the approach to IT professionals working in information security, who believe this may provide improved awareness of how targeted phishing campaigns can impact an organisation, and could contribute towards a pro-active step of how analysts will examine and mitigate the impact of future attacks across the organisation.
引用
收藏
页数:4
相关论文
共 50 条
  • [21] Framework for risk assessment in cyber situational awareness
    Xi Rongrong
    Yun Xiaochun
    Hao Zhiyu
    IET INFORMATION SECURITY, 2019, 13 (02) : 149 - 156
  • [22] Cyber Situational Awareness and Mission-Centric Resilient Cyber Defense
    Lei, Jingmin
    PROCEEDINGS OF 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2015), 2015, : 1218 - 1225
  • [23] Study on Cyber Common Operational Picture Framework for Cyber Situational Awareness
    Kim, Kookjin
    Youn, Jaepil
    Yoon, Sukjoon
    Kang, Jiwon
    Kim, Kyungshin
    Shin, Dongkyoo
    APPLIED SCIENCES-BASEL, 2023, 13 (04):
  • [24] A Novel Approach to Cyber Situational Awareness in Embedded Systems
    Denney, Kyle
    Lychev, Robert
    Kava, Donato
    Lee, Alice
    Vai, Michael
    Evancich, Nick
    Clark, Richard
    Lide, David
    Kwak, K. J.
    Li, Jason
    Lynch, Michael
    Tillotson, Kyle
    Tirenin, Walt
    Schafer, Doug
    2021 IEEE HIGH PERFORMANCE EXTREME COMPUTING CONFERENCE (HPEC), 2021,
  • [25] A COMPARATIVE ANALYSIS AND AWARENESS SURVEY OF PHISHING DETECTION TOOLS
    Sharma, Himani
    Meenakshi, Er.
    Bhatia, Sandeep Kaur
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ELECTRONICS, INFORMATION & COMMUNICATION TECHNOLOGY (RTEICT), 2017, : 1437 - 1442
  • [26] Training to Mitigate Phishing Attacks Using Mindfulness Techniques
    Jensen, Matthew L.
    Dinger, Michael
    Wright, Ryan T.
    Thatcher, Jason Bennett
    JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2017, 34 (02) : 597 - 626
  • [27] Improving Phishing Awareness in the United States Department of Defense
    Dukarm, Christopher
    Dill, Richard
    Reith, Mark
    PROCEEDINGS OF THE 18TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2019), 2019, : 172 - 177
  • [28] Enhancing Cyber Situational Awareness for Cyber-Physical Systems through Digital Twins
    Eckhart, Matthias
    Ekelhart, Andreas
    Weippl, Edgar
    2019 24TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2019, : 1222 - 1225
  • [29] Cyber Situational Awareness Enhancement with Regular Expressions and an Evaluation Methodology
    Park, Hyun Kyoo
    Kim, Min Sik
    park, Moosung
    Lee, Kyungho
    MILCOM 2017 - 2017 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2017, : 406 - 411
  • [30] Towards a Theoretical Framework for an Active Cyber Situational Awareness Model
    Al-Shamisi, Ahmed
    Louvieris, Panos
    Al-Mualla, Mohammed
    Mihajlov, Martin
    PROCEEDINGS OF THE 23RD INTERNATIONAL CONFERENCE ON SYSTEMS, SIGNALS AND IMAGE PROCESSING, (IWSSIP 2016), 2016, : 263 - 268