Protection of external information perimeter of organization from spear phishing

Spear phishing is one of the social engineering techniques. In case of spear phishing the email text is compiled taking into account the knowledge about a particular company and rather often about the employee using sociology and psychology in such a way that cause the desire to open the attached fi...

Full description

Bibliographic Details
Main Authors: Sergey I. Zhurin, Dmitry E. Komarkov
Format: Article
Language:English
Published: Moscow Engineering Physics Institute 2018-12-01
Series:Bezopasnostʹ Informacionnyh Tehnologij
Subjects:
Online Access:https://bit.mephi.ru/index.php/bit/article/view/1164
id doaj-de44c21924c94cea8eb8016eacf4bf84
record_format Article
spelling doaj-de44c21924c94cea8eb8016eacf4bf842020-11-24T20:57:01ZengMoscow Engineering Physics Institute Bezopasnostʹ Informacionnyh Tehnologij2074-71282074-71362018-12-012549610810.26583/bit.2018.4.091121Protection of external information perimeter of organization from spear phishingSergey I. Zhurin0Dmitry E. Komarkov1National Research Nuclear University MEPhI Joint Stock Company "Federal Center of Science and High Technologies "SNPO "Eleron"National Research Nuclear University MEPhISpear phishing is one of the social engineering techniques. In case of spear phishing the email text is compiled taking into account the knowledge about a particular company and rather often about the employee using sociology and psychology in such a way that cause the desire to open the attached file or to click on the link. The main difficulty of protection against such e-mails is that the methods of automated analysis do not guarantee its detection, as modern cyber criminals use new text formulations, zero-day vulnerabilities, as well as automation tools to inject exploits into files, which reduces the effectiveness of signature analysis of anti-virus programs. Each of the existing detection technologies alone does not provide protection against spear phishing. However, the combination of technologies (spam filtering, firewalls, anti-viruses), with the mandatory organizational measures, including training and testing of personnel, allows to protect the external information perimeter of the company from the spear phishing. The paper presents a detailed analysis of the technology of spear phishing implemented by two typical methods: the launch of the exploit when clicking on the link and when one runs an executable file. An overview of the vulnerability used in 2016-2017 for the attacks is presented. Modern technologies of protection and their comparative analysis are given. It is noted that each of the technologies used separately does not allow an effective protection against spear phishing. On the basis of comparative analysis and analysis of modern information threats the most effective modern methods of protection are proposed.https://bit.mephi.ru/index.php/bit/article/view/1164APT, phishing, spearphishing, social engineering, software implementation.
collection DOAJ
language English
format Article
sources DOAJ
author Sergey I. Zhurin
Dmitry E. Komarkov
spellingShingle Sergey I. Zhurin
Dmitry E. Komarkov
Protection of external information perimeter of organization from spear phishing
Bezopasnostʹ Informacionnyh Tehnologij
APT, phishing, spearphishing, social engineering, software implementation.
author_facet Sergey I. Zhurin
Dmitry E. Komarkov
author_sort Sergey I. Zhurin
title Protection of external information perimeter of organization from spear phishing
title_short Protection of external information perimeter of organization from spear phishing
title_full Protection of external information perimeter of organization from spear phishing
title_fullStr Protection of external information perimeter of organization from spear phishing
title_full_unstemmed Protection of external information perimeter of organization from spear phishing
title_sort protection of external information perimeter of organization from spear phishing
publisher Moscow Engineering Physics Institute
series Bezopasnostʹ Informacionnyh Tehnologij
issn 2074-7128
2074-7136
publishDate 2018-12-01
description Spear phishing is one of the social engineering techniques. In case of spear phishing the email text is compiled taking into account the knowledge about a particular company and rather often about the employee using sociology and psychology in such a way that cause the desire to open the attached file or to click on the link. The main difficulty of protection against such e-mails is that the methods of automated analysis do not guarantee its detection, as modern cyber criminals use new text formulations, zero-day vulnerabilities, as well as automation tools to inject exploits into files, which reduces the effectiveness of signature analysis of anti-virus programs. Each of the existing detection technologies alone does not provide protection against spear phishing. However, the combination of technologies (spam filtering, firewalls, anti-viruses), with the mandatory organizational measures, including training and testing of personnel, allows to protect the external information perimeter of the company from the spear phishing. The paper presents a detailed analysis of the technology of spear phishing implemented by two typical methods: the launch of the exploit when clicking on the link and when one runs an executable file. An overview of the vulnerability used in 2016-2017 for the attacks is presented. Modern technologies of protection and their comparative analysis are given. It is noted that each of the technologies used separately does not allow an effective protection against spear phishing. On the basis of comparative analysis and analysis of modern information threats the most effective modern methods of protection are proposed.
topic APT, phishing, spearphishing, social engineering, software implementation.
url https://bit.mephi.ru/index.php/bit/article/view/1164
work_keys_str_mv AT sergeyizhurin protectionofexternalinformationperimeteroforganizationfromspearphishing
AT dmitryekomarkov protectionofexternalinformationperimeteroforganizationfromspearphishing
_version_ 1716788985030770688