paper-with-me

Papers

Different Victims, Same Layout: Email Visual Similarity Detection for Enhanced Email Protection

2024-08-29 · Sachin Shukla, Omid Mirzaei

In the pursuit of an effective spam detection system, the focus has often been on identifying known spam patterns either through rule-based detection systems or machine learning (ML) solutions that rely on keywords. However, both systems are susceptible to evasion techniques and zero-day attacks that can be achieved at low cost. Therefore, an email that bypassed the defense system once can do it again in the following days, even though rules are updated or the ML models are retrained. The recurrence of failures to detect emails that exhibit layout similarities to previously undetected spam is concerning for customers and can erode their trust in a company. Our observations show that threat actors reuse email kits extensively and can bypass detection with little effort, for example, by making changes to the content of emails. In this work, we propose an email visual similarity detection approach, named Pisco, to improve the detection capabilities of an email threat defense system. We apply our proof of concept to some real-world samples received from different sources. Our results show that email kits are being reused extensively and visually similar emails are sent to our customers at various time intervals. Therefore, this method could be very helpful in situations where detection engines that rely on textual features and keywords are bypassed, an occurrence our observations show happens frequently.

📄 PDF Abstract BibTeX arXiv:2408.16945

Code (0)

등록된 구현이 없습니다.

Tasks

Spam detection

Methods 이 논문이 사용한 방법론

Focus 설명 없음

Similar Papers 제목 키워드 기반

Analyzing Social and Stylometric Features to Identify Spear phishing Emails

2014-06-14 · Prateek Dewan, Anand Kashyap, Ponnurangam Kumaraguru

Spear phishing is a complex targeted attack in which, an attacker harvests information about the victim prior to the attack. This information is then used to create sophisticated, genuine-looking attack vectors, drawing …

Automated email Generation for Targeted Attacks using Natural Language

2019-08-19 · Avisha Das, Rakesh Verma

With an increasing number of malicious attacks, the number of people and organizations falling prey to social engineering attacks is proliferating. Despite considerable research in mitigation systems, attackers continual…

Text Generation

Deep Reinforcement Learning for Detecting Malicious Websites

2019-05-22 · Moitrayee Chatterjee, Akbar Siami Namin

Phishing is the simplest form of cybercrime with the objective of baiting people into giving away delicate information such as individually recognizable data, banking and credit card details, or even credentials and pass…

Deep Reinforcement LearningPhishing Website Detectionreinforcement-learningReinforcement Learning+1

Spam Detection Using BERT

2022-06-06 · Thaer Sahmoud, Dr. Mohammad Mikki

Emails and SMSs are the most popular tools in today communications, and as the increase of emails and SMSs users are increase, the number of spams is also increases. Spam is any kind of unwanted, unsolicited digital comm…

Spam detection

The 2021 Hotel-ID to Combat Human Trafficking Competition Dataset

2021-06-10 · Rashmi Kamath, Gregory Rolwes, Samuel Black, Abby Stylianou

Hotel recognition is an important task for human trafficking investigations since victims are often photographed in hotel rooms. Identifying these hotels is vital to trafficking investigations since they can help track d…

Fine-Grained Image Classification