Analysis of Current and Future Phishing Attacks on Internet Banking Services
Stan Hegt · 2008
Management summary This thesis discusses the results of our research into phishing in a Dutch internet banking context. We try to apply a structured approach in order to analyze the current situation and future prospects of phishing. We look at this phenomenon both from the attacker’s and defender’s point of view while maintaining a focus on technological issues. First of all, we derive a definition of phishing. Our definition is broad in the sense that it includes attacks that may not be identified as phishing attacks by other researchers and phishing experts. Our definition abstracts from technology related issues, which allows us to reuse the definition for future attacks. Web-based internet banking services exist for about a decade. In the last few years these services have become established technology in the Netherlands. Nevertheless, confidence in the security of internet banking services remains a critical issue. Phishing is the most apparent class of attacks on these