dc.contributor.author
Veit, Maxime Fabian
dc.contributor.author
Wiese, Oliver
dc.contributor.author
Ballreich, Fabian Lucas
dc.contributor.author
Volkamer, Melanie
dc.contributor.author
Engels, Douglas
dc.contributor.author
Mayer, Peter
dc.date.accessioned
2025-01-13T13:41:56Z
dc.date.available
2025-01-13T13:41:56Z
dc.identifier.uri
https://refubium.fu-berlin.de/handle/fub188/46231
dc.identifier.uri
http://dx.doi.org/10.17169/refubium-45943
dc.description.abstract
User deception in emails is still one of the biggest security risks companies and end-users face alike. Attackers try to mislead their victims when assessing whether emails are dangerous to interact with, e.g., by using techniques based on dangerous links, dangerous attachments, or both. In this work, we present a systematic literature research of deception techniques discussed in the scientific literature of the last decade. We systematize the deception techniques, focusing on techniques that use misleading sender, link, and/or attachment information. We identify 23 deception techniques which we classify as either those that email clients should protect users against (13) and those that email clients cannot protect against and thus should be addressed in security awareness measures (10). We propose a security rating for the susceptibility of email clients to these 13 deception techniques and perform an empirical evaluation to analyze the susceptibility of seven representative email clients (web, mobile apps, desktop apps) to these deception techniques. The results of our evaluation indicate that most email clients are in need of improvement to defend against the deception techniques. Hardening email clients against these deception techniques is necessary to increase the resistance against them — without unnecessarily burdening users.
en
dc.format.extent
18 Seiten
dc.rights.uri
https://creativecommons.org/licenses/by/4.0/
dc.subject
Email clients
en
dc.subject
Deception Techniques
en
dc.subject
Phishing Attacks
en
dc.subject
Human-Computer Interaction
en
dc.subject
Secure Mobile User Interfaces
en
dc.subject
Systemization of Knowledge
en
dc.subject.ddc
000 Informatik, Informationswissenschaft, allgemeine Werke::000 Informatik, Wissen, Systeme::004 Datenverarbeitung; Informatik
dc.title
SoK: The past decade of user deception in emails and today’s email clients’ susceptibility to phishing techniques
dc.type
Wissenschaftlicher Artikel
dcterms.bibliographicCitation.articlenumber
104197
dcterms.bibliographicCitation.doi
10.1016/j.cose.2024.104197
dcterms.bibliographicCitation.journaltitle
Computers & Security
dcterms.bibliographicCitation.volume
150
dcterms.bibliographicCitation.url
https://doi.org/10.1016/j.cose.2024.104197
refubium.affiliation
Mathematik und Informatik
refubium.affiliation.other
Institut für Informatik
refubium.resourceType.isindependentpub
no
dcterms.accessRights.openaire
open access
dcterms.isPartOf.eissn
1872-6208
refubium.resourceType.provider
WoS-Alert