Spears Against Shields
Ayman El Aassal, Rakesh M Verma · 2019
Phishing is the act of using deceptive methods to lure users into taking harmful and dangerous actions against themselves and/or the company they work for. Hackers have been using this method to bypass various security systems, steal personal information, make sensitive data public, and all of this while raking millions of dollars. On the attack side, hackers are using phishing kits and employ all possible phishing techniques to build a successful campaign. On the defense side, we find spam/phishing filters and malicious website detection in addition to anti-phishing simulation training. In this study, we assess the current phishing landscape by testing the tools used on both sides of the war. We generated 1,000 phishing emails containing phishing links semi-automatically using natural language generation technology and tested five popular tools with anti-phishing modules. The number of undetected emails ranged from 77 to 927. We also evaluate several anti-phishing training technologies and reveal their shortcomings. Our results suggest that both anti-phishing filters and current training tools have a long way to go and thus improving these defense mechanisms is still essential.