KIT | KIT-Bibliothek | Impressum | Datenschutz

SoK: The past decade of user deception in emails and today’s email clients’ susceptibility to phishing techniques

Veit, Maxime Fabian ORCID iD icon 1; Wiese, Oliver; Ballreich, Fabian Lucas ORCID iD icon 1; Volkamer, Melanie 1; Engels, Douglas; Mayer, Peter ORCID iD icon 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)

Abstract:

User deception in emails is still one of the biggest security risks companies and end-users face alike. Attackers try to mislead their victims when assessing whether emails are dangerous to interact with, e.g., by using techniques based on dangerous links, dangerous attachments, or both. In this work, we present a systematic literature research of deception techniques discussed in the scientific literature of the last decade. We systematize the deception techniques, focusing on techniques that use misleading sender, link, and/or attachment information. We identify 23 deception techniques which we classify as either those that email clients should protect users against (13) and those that email clients cannot protect against and thus should be addressed in security awareness measures (10). We propose a security rating for the susceptibility of email clients to these 13 deception techniques and perform an empirical evaluation to analyze the susceptibility of seven representative email clients (web, mobile apps, desktop apps) to these deception techniques. The results of our evaluation indicate that most email clients are in need of improvement to defend against the deception techniques. ... mehr


Verlagsausgabe §
DOI: 10.5445/IR/1000177225
Veröffentlicht am 11.12.2024
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Institut für Informationssicherheit und Verlässlichkeit (KASTEL)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Zeitschriftenaufsatz
Publikationsmonat/-jahr 03.2025
Sprache Englisch
Identifikator ISSN: 0167-4048
KITopen-ID: 1000177225
HGF-Programm 46.23.02 (POF IV, LK 01) Engineering Security for Energy Systems
Erschienen in Computers & Security
Verlag Elsevier
Band 150
Seiten 104197
Schlagwörter Email, Email clients, Deception Techniques, Phishing Attacks, Human-Computer Interaction, Secure Mobile User Interfaces, Systematization of Knowledge
Nachgewiesen in Dimensions
Web of Science
Scopus
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page