Don’t Forget the Human: a Crowdsourced Approach to Automate Response and Containment Against Spear Phishing Attacks

In IEEE European Symposium on Security and Privacy Workshops (EuroS&PW 2020), 2020

Burda, P.; Allodi, L.; Zannone, N.;

Abstract

Organizations are increasingly facing sophisticated social engineering attacks that exploit human vulnerabilities and overcome commonly available countermeasures. Spear-phishing campaigns are becoming the most prevalent attack and source of compromise for most organizations. We argue that existing prevention and detection countermeasures are fundamentally ineffective against this class of attacks. In this work, we propose a novel approach to address the limitations of existing countermeasures. Our proposition is a new course of action to exploit human detection capabilities as a basis of automated response strategies. Preliminary results unveil users' mental models for phishing detection and reporting as a way to improve the phishing reporting process altogether. A real word case study is provided to promote the feasibility of our proposal.

URL: https://doi.org/10.1109/EuroSPW51379.2020.00069

Bib