Visible to the public No Phishing With the Wrong Bait: Reducing the Phishing Risk by Address Separation

TitleNo Phishing With the Wrong Bait: Reducing the Phishing Risk by Address Separation
Publication TypeConference Paper
Year of Publication2020
AuthorsDrury, Vincent, Meyer, Ulrike
Conference Name2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
KeywordsElectronic mail, Human Behavior, phishing, pubcrawl, Registers, security, Taxonomy, unsolicited e-mail, usability
AbstractEmail-based phishing is still a widespread problem, that affects many users worldwide. Although many aspects of phishing have been extensively studied in the past, they mainly focus on the execution and prevention of different types of phishing and do not consider the process how attackers collect the contact information of potential victims. In this paper, we analyze the collection process of email addresses in more detail. Based on the results of this analysis, we propose email address separation as a way for users to detect phishing emails, and reason about its effectiveness against several typical types of phishing attacks. We find, that email address separation has the potential to greatly reduce the perceived authenticity of general phishing emails, that target a large amount of users, e.g., by impersonating a popular service and spreading malware or links to phishing websites. It is, however, not likely to prevent more sophisticated phishing attacks, that do not depend on the impersonation of a previously known organization or entity. Our results motivate further studies to analyze the usability and applicability of the proposed method, and to determine, whether address separation has additional positive effects on users' phishing awareness or automated phishing detection.
DOI10.1109/EuroSPW51379.2020.00093
Citation Keydrury_no_2020