USENIX Security2019Top-tier venue
Detecting and Characterizing Lateral Phishing at Scale
Grant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser, Vern Paxson, Stefan Savage, Geoffrey M. Voelker, David A. Wagner
Abstract
Author(s): Ho, G; Cidon, A; Gavish, L; Schweighauser, M; Paxson, V; Savage, S; Voelker, GM; Wagner, D | Abstract: © 2019 by The USENIX Association. All rights reserved. We present the first large-scale characterization of lateral phishing attacks, based on a dataset of 113 million employee-sent emails from 92 enterprise organizations. In a lateral phishing attack, adversaries leverage a compromised enterprise account to send phishing emails to other users, benefit-ting from both the implicit trust and the information in the hijacked user's account. We develop a classifier that finds hundreds of real-world lateral phishing emails, while generating under four false positives per every one-million employee-sent emails. Drawing on the attacks we detect, as well as a corpus of user-reported incidents, we quantify the scale of lateral phishing, identify several thematic content and recipient targeting strategies that attackers follow, illuminate two types of sophisticated behaviors that attackers exhibit, and estimate the success rate of these attacks. Collectively, these results expand our mental models of the 'enterprise attacker' and shed light on the current state of enterprise phishing attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 026343b8-28bd-4be9-8913-8ec2ff59536fCited by top-tier papers21
- High Precision Detection of Business Email CompromiseAsaf Cidon, Lior Gavish, Itay Bleier, Nadia Korshun et al.USENIX Security 2019 · 68 citations
- Cost-Aware Robust Tree Ensembles for Security ApplicationsYizheng Chen, Shiqi Wang, Weifan Jiang, Asaf Cidon et al.USENIX Security 2021 · 26 citations
- A Case Study of Phishing Incident Response in an Educational OrganizationKholoud Althobaiti, Adam D. G. Jenkins, Kami VanieaCSCW 2021 · 25 citations
- Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at ScaleMichele Campobasso, Luca AllodiCCS 2020 · 24 citations
- Phishing URL Detection: A Network-based Approach Robust to EvasionTaeri Kim, Noseong Park, Jiwon Hong, Sang-Wook KimCCS 2022 · 21 citations
Builds on3
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and TimeFeargus Pendlebury, Fabio Pierazzi, Roberto Jordaney, Johannes Kinder et al.USENIX Security 2019 · 441 citations
- High Precision Detection of Business Email CompromiseAsaf Cidon, Lior Gavish, Itay Bleier, Nadia Korshun et al.USENIX Security 2019 · 68 citations
- A Broad View of the Ecosystem of Socially Engineered Exploit DocumentsStevens Le Blond, Cédric Gilbert, Utkarsh Upadhyay, Manuel Gomez-Rodriguez et al.NDSS 2017 · 20 citations
Related papers
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson et al.USENIX Security 2017 · 94 citations
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 92 citations
- Hopper: Modeling and Detecting Lateral MovementGrant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson et al.USENIX Security 2021 · 41 citations
- What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing DecisionsAnne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das et al.CSCW 2023 · 11 citations
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen et al.CCS 2024 · 9 citations
