How Spear Phishing (Targeted Scam) Detection Works

How Spear Phishing (Targeted Scam) Detection Works Featured Image

There’s an offshoot of email scamming techniques that is starting to make the rounds, and it’s called spear phishing. This new kind of phishing has been on a steady upward trend since 2015, making companies suffer massive losses and draining millions of dollars from the economy into the hands of enterprising hackers.

It’s received so much attention in recent years that on 18 August 2017, Facebook awarded its annual Internet Defense Prize to a group of researchers from the University of California, Berkeley, that managed to create an automated spear phishing detection project. They’ve published a helpful paper on the subject which will help us get to the brass tacks of how spear phishing detection should work in a corporate environment.

What Makes Spear Phishing Such a Threat

security-lock-on-credit-cards-with-a-fish-hook-note-shallow-depth-of-field

If you want a rundown on what spear phishing is, I’ve already written about it at length in this article. The level of sophistication in a spear phishing attack can differ according to the resources available to the hacker.

But in general, the goal is to create an email that perfectly mimics what the victim would receive from a trusted individual. This means that these particular emails will often lack the signs of a scam message. Since it looks legitimate, it gets the victim’s guard down, making them more susceptible to inadvertently doing harm to themselves or the companies where they are employed.

Here’s the scary part: the email message could even come from the address of someone the victim trusts, spoofing the name and other details and throwing traditional detection methods off its scent.

How Algorithms Spot the Emails

spearphishing-detection

Despite the fact that spear phishing emails typically look very legitimate in comparison to the messages distributed using the traditional “lottery” phishing style, the spear isn’t as sharp as it looks. Every fake message has its tell. In this particular case it’s all about making a simple heuristic analysis of all the messages sent to and from the victim, spotting patterns in both the language of the body and content of the header in the email.

If you, for example, have a contact that usually messages you from the United States and suddenly receive a message from that same contact originating from Nigeria, that could be a red flag. The algorithm, known as Directed Anomaly Scoring (DAS) also looks at the message itself for signs of suspicious content. For example, if there is a link within the email to a website and the system notices that no other employees in your company have visited it, this could be marked as something suspicious. The message could be further analyzed to determine the “reputability” of the URLs contained within.

Since most attackers will only spoof the sender name and not their email address, the algorithm may also try to correlate the sender name to an email used within the last few months. If the sender name and email do not correspond to anything used in the past, that will raise alarms.

In a nutshell, the DAS algorithm will scan the content of the email, its header, and corporate LDAP logs to make a decision on whether the email results from a spear phishing attempt or is just a weird, but legitimate message. In its test run analyzing 370 million emails, DAS has detected 17 out of 19 attempts and had a false positive rate of 0.004%. Not bad!

Now here’s another issue: Do you think that email scanners violate the privacy of individuals, even when used in a closed corporate environment purely for the detection of scams? Let’s discuss this in the comments!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

When you type an address into a browser, your computer first asks a DNS resolver for the site’s IP — a query that may bounce through your router, your ISP, and one of just 13 root server clusters before the page ever begins to load
Voyager 1 is still transmitting from more than 25 billion kilometres away, powered by less than 250 watts of decaying plutonium — a signal that now takes over 23 hours to reach Earth, carried by a radio no stronger than a refrigerator lightbulb
In September 1947, engineers at Harvard pulled a moth from a relay inside the Mark II computer, taped it into the logbook, and wrote ‘first actual case of bug being found’ — the pest was literal
When Sony shipped the first Walkman in 1979, chairman Akio Morita insisted on a second headphone jack and a “hotline” talk button, convinced it would be rude for one person to listen to music alone — and within a few years buyers had ignored the sociable features so completely that Sony quietly dropped them
Russia still custom-builds the Soyuz return seats for ISS crew members using plaster casts taken weeks before launch, because astronauts grow as much as five centimetres taller during a long-duration stay and a seat moulded to their Earth-shaped spine would no longer fit the body that comes home
The “CrackBerry” nickname stuck for a reason — and the variable-reward psychology that hooked early-2000s executives on their BlackBerrys is the exact same machinery now running every push notification on every smartphone in your pocket
In 1843, Ada Lovelace described a brass-and-punched-card engine that could act on symbols as well as numbers, even composing music if harmony could be reduced to rules, inside seven translator’s notes three times longer than the paper itself
ARPANET sent its first message on 29 October 1969 from a lab at UCLA to a machine at Stanford, and the message was supposed to read ‘LOGIN’ — but the system crashed after the L and the O, meaning the first word ever transmitted over the network that became the internet was, by accident, ‘LO’.