首页 | 本学科首页   官方微博 | 高级检索  
     


A recent review of conventional vs. automated cybersecurity anti-phishing techniques
Affiliation:1. Applied Business and Computing, NMIT, Auckland;2. Center of Computational Intelligence, School of Computer Science and Informatics, De Montfort University, Leicester, UK;1. Karlstad University, Karlstad, Sweden;2. Technische Universität Darmstadt, Darmstadt, Germany;3. University of Glasgow, Glasgow, UK;1. Federal University of Pernambuco, Center of Informatics (CIn/UFPE) P.O. Box 7851, Recife-PE, Brazil;2. University of Pernambuco (UPE), Garanhuns-PE, ZIP 55294-902, Brazil;3. Federal University of Amazonas, Computing Institute (IComp/UFAM) ZIP 69077-000, Manaus-PE, Brazil
Abstract:In the era of electronic and mobile commerce, massive numbers of financial transactions are conducted online on daily basis, which created potential fraudulent opportunities. A common fraudulent activity that involves creating a replica of a trustful website to deceive users and illegally obtain their credentials is website phishing. Website phishing is a serious online fraud, costing banks, online users, governments, and other organisations severe financial damages. One conventional approach to combat phishing is to raise awareness and educate novice users on the different tactics utilised by phishers by conducting periodic training or workshops. However, this approach has been criticised of being not cost effective as phishing tactics are constantly changing besides it may require high operational cost. Another anti-phishing approach is to legislate or amend existing cyber security laws that persecute online fraudsters without minimising its severity. A more promising anti-phishing approach is to prevent phishing attacks using intelligent machine learning (ML) technology. Using this technology, a classification system is integrated in the browser in which it will detect phishing activities and communicate these with the end user. This paper reviews and critically analyses legal, training, educational and intelligent anti-phishing approaches. More importantly, ways to combat phishing by intelligent and conventional are highlighted, besides revealing these approaches differences, similarities and positive and negative aspects from the user and performance prospective. Different stakeholders such as computer security experts, researchers in web security as well as business owners may likely benefit from this review on website phishing.
Keywords:Classification  Computer security  Phishing  Machine learning  Web security  Security awareness
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号