Study on security policy options for responding to phishing
Eungyong Lee, Yoongjung Kim · International Conference on Information Security · 2006
Phishing is targeted financial scam in which attacker uses social engineering and spyware, malicious code methods to steal personal data such as credit card numbers. Many companies are trying to protect themselves and customers by seeking solutions designed to stop phishing. However no safeguard is perfect. For a phishing attack, Phishers use a number of methods to trick internet users such as man-in-the-middle attacks, URL obfuscation, observing user data, cross-site scripting attacks, hidden attacks. Phishing countermeasures are technological, social, legal ones. And we propose political options. Government's security agencies should assess pishiing risk, and establish government-wide guidance, and improve citizen's phishing-awareness, and establish governmental collaboration system for coping with phishing, and revise legal system.