How Spear Phishing (Targeted Scam) Detection Works

How Spear Phishing (Targeted Scam) Detection Works Featured Image

There’s an offshoot of email scamming techniques that is starting to make the rounds, and it’s called spear phishing. This new kind of phishing has been on a steady upward trend since 2015, making companies suffer massive losses and draining millions of dollars from the economy into the hands of enterprising hackers.

It’s received so much attention in recent years that on 18 August 2017, Facebook awarded its annual Internet Defense Prize to a group of researchers from the University of California, Berkeley, that managed to create an automated spear phishing detection project. They’ve published a helpful paper on the subject which will help us get to the brass tacks of how spear phishing detection should work in a corporate environment.

What Makes Spear Phishing Such a Threat

security-lock-on-credit-cards-with-a-fish-hook-note-shallow-depth-of-field

If you want a rundown on what spear phishing is, I’ve already written about it at length in this article. The level of sophistication in a spear phishing attack can differ according to the resources available to the hacker.

But in general, the goal is to create an email that perfectly mimics what the victim would receive from a trusted individual. This means that these particular emails will often lack the signs of a scam message. Since it looks legitimate, it gets the victim’s guard down, making them more susceptible to inadvertently doing harm to themselves or the companies where they are employed.

Here’s the scary part: the email message could even come from the address of someone the victim trusts, spoofing the name and other details and throwing traditional detection methods off its scent.

How Algorithms Spot the Emails

spearphishing-detection

Despite the fact that spear phishing emails typically look very legitimate in comparison to the messages distributed using the traditional “lottery” phishing style, the spear isn’t as sharp as it looks. Every fake message has its tell. In this particular case it’s all about making a simple heuristic analysis of all the messages sent to and from the victim, spotting patterns in both the language of the body and content of the header in the email.

If you, for example, have a contact that usually messages you from the United States and suddenly receive a message from that same contact originating from Nigeria, that could be a red flag. The algorithm, known as Directed Anomaly Scoring (DAS) also looks at the message itself for signs of suspicious content. For example, if there is a link within the email to a website and the system notices that no other employees in your company have visited it, this could be marked as something suspicious. The message could be further analyzed to determine the “reputability” of the URLs contained within.

Since most attackers will only spoof the sender name and not their email address, the algorithm may also try to correlate the sender name to an email used within the last few months. If the sender name and email do not correspond to anything used in the past, that will raise alarms.

In a nutshell, the DAS algorithm will scan the content of the email, its header, and corporate LDAP logs to make a decision on whether the email results from a spear phishing attempt or is just a weird, but legitimate message. In its test run analyzing 370 million emails, DAS has detected 17 out of 19 attempts and had a false positive rate of 0.004%. Not bad!

Now here’s another issue: Do you think that email scanners violate the privacy of individuals, even when used in a closed corporate environment purely for the detection of scams? Let’s discuss this in the comments!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

In 1965, Joe Sutter’s Boeing team began shaping the 747 around a future they thought would belong to supersonic jets, lifting the cockpit onto a hump so the nose could open for cargo once the giant subsonic passenger plane had outlived its brief moment
Apple’s original 1984 Macintosh keyboard had no arrow keys, no function keys, and no numeric pad because Steve Jobs wanted users to reach for the mouse first. Then Apple quietly sold the missing keys as an accessory.
When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
Masahiro Hara and Denso engineers built the QR code in 1994 to help Toyota suppliers scan car parts from any angle, then kept the patent open until phone cameras and a 2020 pandemic turned the factory square into a daily ritual on restaurant tables
In 1965, Mary Allen Wilkes wrote LAP6 for the LINC computer from her parents’ Baltimore home, testing an interactive operating system on a 250-pound machine in the living room and becoming the first known person to use a personal computer at home, twelve years before the Apple II reached buyers
When Grace Hopper wanted to explain a nanosecond to admirals who kept asking why satellites were slow, she handed each of them a piece of wire 11.8 inches long, the exact distance light travels in a billionth of a second, and told them to keep it in their pocket as a reminder that physics, not laziness, sets the limit.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
When Doug Wheelock came home after 163 days in space, he said he had craved the aroma of leaves, grass, flowers, and trees, the rush of Earthiness that reaches astronauts only when the hatch opens back onto the living planet