USENIX Security2019Top-tier venue
High Precision Detection of Business Email Compromise
Asaf Cidon, Lior Gavish, Itay Bleier, Nadia Korshun, Marco Schweighauser, Alexey Tsitkin
Abstract
Business email compromise (BEC) and employee impersonation have become one of the most costly cyber-security threats, causing over $12 billion in reported losses. Impersonation emails take several forms: for example, some ask for a wire transfer to the attacker's account, while others lead the recipient to following a link, which compromises their credentials. Email security systems are not effective in detecting these attacks, because the attacks do not contain a clearly malicious payload, and are personalized to the recipient. We present BEC-Guard, a detector used at Barracuda Networks that prevents business email compromise attacks in real-time using supervised learning. BEC-Guard has been in production since July 2017, and is part of the Barracuda Sentinel email security product. BEC-Guard detects attacks by relying on statistics about the historical email patterns that can be accessed via cloud email provider APIs. The two main challenges when designing BEC-Guard are the need to label millions of emails to train its classifiers, and to properly train the classifiers when the occurrence of employee impersonation emails is very rare, which can bias the classification. Our key insight is to split the classification problem into two parts, one analyzing the header of the email, and the second applying natural language processing to detect phrases associated with BEC or suspicious links in the email body. BEC-Guard utilizes the public APIs of cloud email providers both to automatically learn the historical communication patterns of each organization, and to quarantine emails in real-time. We evaluated BEC-Guard on a commercial dataset containing more than 4,000 attacks, and show it achieves a precision of 98.2% and a false positive rate of less than one in five million emails.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cf0b77a4-e879-40c5-ad70-3e6892c23abcCited by top-tier papers10
- Detecting and Characterizing Lateral Phishing at ScaleGrant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser et al.USENIX Security 2019 · 113 citations
- Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing AttacksKaiwen Shen, Chuhan Wang, Minglei Guo, Xiaofeng Zheng et al.USENIX Security 2021 · 49 citations
- Cost-Aware Robust Tree Ensembles for Security ApplicationsYizheng Chen, Shiqi Wang, Weifan Jiang, Asaf Cidon et al.USENIX Security 2021 · 26 citations
- A Case Study of Phishing Incident Response in an Educational OrganizationKholoud Althobaiti, Adam D. G. Jenkins, Kami VanieaCSCW 2021 · 25 citations
- ATTention Please! An Investigation of the App Tracking Transparency PermissionReham Mohamed, Arjun Arunasalam, Habiba Farrukh, Jason Tong et al.USENIX Security 2024 · 9 citations
Builds on2
- Detecting and Characterizing Lateral Phishing at ScaleGrant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser et al.USENIX Security 2019 · 113 citations
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson et al.USENIX Security 2017 · 94 citations
Related papers
- Unfiltered: Measuring Cloud-based Email Filtering BypassesSumanth Rao, Enze Liu, Grant Ho, Geoffrey M. Voelker et al.WWW 2024 · 1 citation
- Towards High-Performance Intrusion Detection with Robustness Guarantees on Programmable Switches at ISP ScaleHan Zhang, Xuefeng Liu, Linqiang Qian, Guyue (Grace) Liu et al.SIGCOMM 2026
- Optimized Invariant Representation of Network Traffic for Detecting Unseen Malware VariantsKarel Bartos, Michal Sofka, Vojtech FrancUSENIX Security 2016 · 147 citations
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong et al.S&P 2025
- Safeguarding Blockchain Ecosystem: Understanding and Detecting Attack Transactions on Cross-chain BridgesJiajing Wu, Kaixin Lin, Dan Lin, Bozhao Zhang et al.WWW 2025 · 20 citations
