论文标题

网络钓鱼和矛网络钓鱼:网络间谍活动和技术的示例以防止它们

Phishing and Spear Phishing: examples in Cyber Espionage and techniques to protect against them

论文作者

Agazzi, Alessandro Ecclesie

论文摘要

从2012年开始,网络钓鱼攻击已成为在线骗局中最常用的技术,启动了超过91%的网络攻击。这项研究回顾了网络钓鱼和矛网络钓鱼攻击是如何通过5个步骤来放大结果的5个步骤,从而增加了成功的机会。重点也将放在四个不同的保护层面,以防止这些社会工程攻击,表明它们的优势和劣势。第一层和第二层由自动化工具和决策AID工具组成。第三个是用户的知识和专业知识来应对潜在威胁。最后一层被定义为“外部”,将强调具有多因素身份验证的重要性,这是提供增强安全性的有效方法,从而进一步保护网络钓鱼和长矛网络钓鱼。

Phishing attacks have become the most used technique in the online scams, initiating more than 91% of cyberattacks, from 2012 onwards. This study reviews how Phishing and Spear Phishing attacks are carried out by the phishers, through 5 steps which magnify the outcome, increasing the chance of success. The focus will be also given on four different layers of protection against these social engineering attacks, showing their strengths and weaknesses; the first and second layers consist of automated tools and decision-aid tools. the third one is users' knowledge and expertise to deal with potential threats. The last layer, defined as "external", will underline the importance of having a Multi-factor authentication, an effective way to provide an enhanced security, creating a further layer of protection against Phishing and Spear Phishing.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源