USENIX Security2017Top-tier venue
Detecting Credential Spearphishing in Enterprise Settings
Grant Ho, Aashish Sharma, Mobin Javed, Vern Paxson, David A. Wagner
Abstract
We present a new approach for detecting credential spearphishing attacks in enterprise settings. Our method uses features derived from an analysis of fundamental characteristics of spearphishing attacks, combined with a new non-parametric anomaly scoring technique for ranking alerts. We evaluate our technique on a multi-year dataset of over 370 million emails from a large enterprise with thousands of employees. Our system successfully detects 6 known spearphishing campaigns that succeeded (missing one instance); an additional 9 that failed; plus 2 successful spearphishing attacks that were previously unknown, thus demonstrating the value of our approach. We also establish that our detector's false positive rate is low enough to be practical: on average, a single analyst can investigate an entire month's worth of alerts in under 15 minutes. Comparing our anomaly scoring method against standard anomaly detection techniques, we find that standard techniques using the same features would need to generate at least 9 times as many alerts as our method to detect the same number of attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2b2a2246-683b-4be5-a7f9-9dfa4900d4f0Cited by top-tier papers24
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- Tiresias: Predicting Security Events Through Deep LearningYun Shen, Enrico Mariconti, Pierre-Antoine Vervier, Gianluca StringhiniCCS 2018 · 180 citations
- Skill Squatting Attacks on Amazon AlexaDeepak Kumar, Riccardo Paccagnella, Paul Murley, Eric Hennenfent et al.USENIX Security 2018 · 177 citations
- End-to-End Measurements of Email Spoofing AttacksHang Hu, Gang WangUSENIX Security 2018 · 94 citations
- DEEPCASE: Semi-Supervised Contextual Analysis of Security EventsThijs van Ede, Hojjat Aghakhani, Noah Spahn, Riccardo Bortolameotti et al.S&P 2022 · 91 citations
Builds on1
Related papers
- Detecting and Characterizing Lateral Phishing at ScaleGrant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser et al.USENIX Security 2019 · 113 citations
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 92 citations
- Sunrise to Sunset: Analyzing the End-to-end Life Cycle and Effectiveness of Phishing Attacks at ScaleAdam Oest, Penghui Zhang, Brad Wardman, Eric Nunes et al.USENIX Security 2020
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong et al.S&P 2025
- True Attacks, Attack Attempts, or Benign Triggers? An Empirical Measurement of Network Alerts in a Security Operations CenterLimin Yang, Zhi Chen, Chenkai Wang, Zhenning Zhang et al.USENIX Security 2024 · 16 citations
