Skip to main content

Protect Against Phishing Scams

Page 1

ISSN 2348-1196 (print) International Journal of Computer Science and Information Technology Research ISSN 2348-120X (online) Vol. 10, Issue 2, pp: (82-86), Month: April - June 2022, Available at: www.researchpublish.com

Protect Against Phishing Scams 1

Junaid Jan, 2Mohammed Mujtaba, 3Qasim T. Zaidi, 4Zaki S. Ahmed Saudi Arabian Oil Company, Dhahran, Kingdom of Saudi Arabia DOI: https://doi.org/10.5281/zenodo.6616588

Published Date: 07-June-2022

Abstract: Phishing is an act of luring unsuspecting recipient of a message into revealing information which can be used against the recipient. Email is the most common medium of creating a Phishing attack against individuals and organizations. Phishing is a type of social engineering attempt, usually via emails, designed to trick the recipient. These attacks often result in malicious software getting deployed, steal user data including credentials or financial data, and victimize the entire infrastructure for ransom etc. First step in preventing this attack is to identify what a Phishing attempt is, to report it, and take similar actions for others. The golden rule of prevention is when you are in doubt, do not open that email, download its attachments or click on any hyperlinks inside. Keywords: Phishing, Spam, Email, Malware, Social Engineering.

I. INTRODUCTION According to Phishing.org, a website for IT professionals to make smarter security decisions related to email security, phishing is defined as “a cybercrime in which a target or targets are contacted by email, telephone or text message by someone posing as a legitimate institution to lure individuals into providing sensitive data such as personally identifiable information, banking and credit card details, and passwords.” All of us have experienced receiving an email which seemed legitimate and from a known entity, whether it be a person we recognized, an unknown wealthy and generous person willing to part from a percent of his/her savings, or more commonly an organization offering an opportunity such as a free Apple iPhone. All these and many others are examples of attempts to gain access to our personal information which could be instrumental for an attacker or a group of attackers to cause either financial damage or use it to inject malware for some form of ransom. This research paper briefly discusses the common themes of the phishing attacks and ways we can protect ourselves and the organization we work for, from revealing sensitive information thereby preventing the attack from ever taking shape. The paper focuses primarily on email as it is the most common means of spearheading a phishing campaign, making individuals and infrastructures vulnerable to cybercriminals. The paper also provides simple techniques as well as advanced features available to individuals and organizations for lowering the potential of a compromise cause by phishing attacks. The mitigations included in this paper is approaches consisting of technology, process, and people; together these defences can be really effective in thwarting the email-based phishing attacks. Explanation of the terms used extensively in this paper Term Phishing

Attacker Malware Social Engineering Internet Email Gateways

Explanation Phishing is a type of social engineering where an attacker sends a fraudulent (e.g., spoofed, fake, or otherwise deceptive) message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious software on the victim's infrastructure like ransomware. Read more here A person, a group, or a program determined to lure individuals into providing sensitive data. This data is often used to create a Phishing attack. Software that is specifically designed to disrupt, damage, or gain unauthorized access to a computer system. In the context of information security, social engineering is the psychological manipulation of people into performing actions or divulging confidential information. More here An email gateway is a type of email server that protects an organizations or users internal email servers. This server acts as a gateway through which every incoming and outgoing email passes through

Page | 82 Research Publish Journals


Turn static files into dynamic content formats.

Create a flipbook