How Spear Phishing (Targeted Scam) Detection Works

How Spear Phishing (Targeted Scam) Detection Works Featured Image

There’s an offshoot of email scamming techniques that is starting to make the rounds, and it’s called spear phishing. This new kind of phishing has been on a steady upward trend since 2015, making companies suffer massive losses and draining millions of dollars from the economy into the hands of enterprising hackers.

It’s received so much attention in recent years that on 18 August 2017, Facebook awarded its annual Internet Defense Prize to a group of researchers from the University of California, Berkeley, that managed to create an automated spear phishing detection project. They’ve published a helpful paper on the subject which will help us get to the brass tacks of how spear phishing detection should work in a corporate environment.

What Makes Spear Phishing Such a Threat

security-lock-on-credit-cards-with-a-fish-hook-note-shallow-depth-of-field

If you want a rundown on what spear phishing is, I’ve already written about it at length in this article. The level of sophistication in a spear phishing attack can differ according to the resources available to the hacker.

But in general, the goal is to create an email that perfectly mimics what the victim would receive from a trusted individual. This means that these particular emails will often lack the signs of a scam message. Since it looks legitimate, it gets the victim’s guard down, making them more susceptible to inadvertently doing harm to themselves or the companies where they are employed.

Here’s the scary part: the email message could even come from the address of someone the victim trusts, spoofing the name and other details and throwing traditional detection methods off its scent.

How Algorithms Spot the Emails

spearphishing-detection

Despite the fact that spear phishing emails typically look very legitimate in comparison to the messages distributed using the traditional “lottery” phishing style, the spear isn’t as sharp as it looks. Every fake message has its tell. In this particular case it’s all about making a simple heuristic analysis of all the messages sent to and from the victim, spotting patterns in both the language of the body and content of the header in the email.

If you, for example, have a contact that usually messages you from the United States and suddenly receive a message from that same contact originating from Nigeria, that could be a red flag. The algorithm, known as Directed Anomaly Scoring (DAS) also looks at the message itself for signs of suspicious content. For example, if there is a link within the email to a website and the system notices that no other employees in your company have visited it, this could be marked as something suspicious. The message could be further analyzed to determine the “reputability” of the URLs contained within.

Since most attackers will only spoof the sender name and not their email address, the algorithm may also try to correlate the sender name to an email used within the last few months. If the sender name and email do not correspond to anything used in the past, that will raise alarms.

In a nutshell, the DAS algorithm will scan the content of the email, its header, and corporate LDAP logs to make a decision on whether the email results from a spear phishing attempt or is just a weird, but legitimate message. In its test run analyzing 370 million emails, DAS has detected 17 out of 19 attempts and had a false positive rate of 0.004%. Not bad!

Now here’s another issue: Do you think that email scanners violate the privacy of individuals, even when used in a closed corporate environment purely for the detection of scams? Let’s discuss this in the comments!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

When Sony shipped the first Walkman in 1979, chairman Akio Morita insisted on a second headphone jack and a “hotline” talk button, convinced it would be rude for one person to listen to music alone — and within a few years buyers had ignored the sociable features so completely that Sony quietly dropped them
Russia still custom-builds the Soyuz return seats for ISS crew members using plaster casts taken weeks before launch, because astronauts grow as much as five centimetres taller during a long-duration stay and a seat moulded to their Earth-shaped spine would no longer fit the body that comes home
The “CrackBerry” nickname stuck for a reason — and the variable-reward psychology that hooked early-2000s executives on their BlackBerrys is the exact same machinery now running every push notification on every smartphone in your pocket
In 1843, Ada Lovelace described a brass-and-punched-card engine that could act on symbols as well as numbers, even composing music if harmony could be reduced to rules, inside seven translator’s notes three times longer than the paper itself
ARPANET sent its first message on 29 October 1969 from a lab at UCLA to a machine at Stanford, and the message was supposed to read ‘LOGIN’ — but the system crashed after the L and the O, meaning the first word ever transmitted over the network that became the internet was, by accident, ‘LO’.
In 1995, Microsoft shipped a cartoon-house interface called Bob, led by Melinda French, who married Bill Gates while it was in development — it demanded twice the memory of a typical home PC, sold roughly 30,000 copies, and was dead within a year, leaving behind the font Comic Sans and the animated assistant that became Clippy.
The Greenland shark grows about one centimetre a year, does not reach sexual maturity until around age 150, and a specimen carbon-dated by Danish researchers in 2016 was estimated to be at least 272 years old, meaning it was already swimming the North Atlantic when Mozart was composing symphonies.
When Apple shipped iOS 12 in June 2018, a small feature called Screen Time slipped onto every iPhone with a counter nobody had quite prepared for — a tally of pickups — and within a day Tim Cook was telling CNN the number of times he picked up his own phone was simply too many